A reported Python framework ties together wireless credential extraction, disruption, proxy use, and DDoS-style traffic, showing how a single script can mix access, control, and impact.
A newly described intrusion set used Telegram bots for command and control, then layered in obfuscation and environment-bound payloads to make analysis and detection harder.
A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.
A newly examined malware chain shows how attackers can hide command-and-control inside a trusted messaging service while using layered loaders and host-bound checks to slow defenders down.
A reported macOS infostealer shows how stolen sessions, browser secrets, and fake wallet launch paths can move a single endpoint problem into account and crypto risk.
A Telegram lure impersonating UniCredit points to a deeper mobile threat: an Android banking trojan built for on-device fraud, not simple password theft.
Telegram’s t.me links stopped resolving after a .ME registry status change, showing how a public entry point can fail even when the underlying app still works.
A worldwide t.me suspension shows how a seemingly small naming layer can interrupt browser access, automation, and fast-moving workflows that depend on it.
A status change on t.me shows how one domain can sit at the center of a messaging platform’s identity, sharing, and access paths.
A registry-level hold on t.me shows how a single domain action can disrupt Telegram's link ecosystem worldwide while the main app may still be reachable.
A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.
A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.
A critical flaw in a Telegram-facing MCP server shows how a bearer token can become dangerous when authentication logic is entangled with filesystem-based session handling.
A critical flaw in a Telegram MCP gateway shows how a single filesystem mistake can turn bearer-token authentication into an unexpected route into a live account session.
A Python-based infostealer is being tracked as a focused grab for browser logins, Telegram sessions, screenshots, clipboard data, and crypto material - a reminder that one endpoint can hold many forms of usable trust.
A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.
The malware’s latest variant pairs resource-embedded settings with Base64 and XOR obfuscation, making its control plane harder to spot without deeper binary triage.
A Windows remote-access trojan tied to a MaaS model is being linked to Telegram Bot API tasking and a move away from .NET toward native C++ code.
Group-IB’s analysis of Millenium RAT v4.* ties 62,289 Windows infections in more than 160 countries to Telegram bot communication, a combination that can blur malicious traffic inside ordinary cloud use.
A Rust-based implant tied to a DPRK-linked macOS cluster pairs ordinary startup persistence with a Python stealer stage and prompt-injection text aimed at analysts.