Lunes 27 Julio 2026 07:44:09 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#Telegram


Telegram-Controlled Tooling Blends WiFi Credential Hunts With Network Flooding

Published: 22 July 2026 10:28Category: Malware & BotnetsAuthor: IRONQUERY

A reported Python framework ties together wireless credential extraction, disruption, proxy use, and DDoS-style traffic, showing how a single script can mix access, control, and impact.

Telegram as a Quiet Control Room: The Malware Chain That Hid Behind Normal Messaging

Published: 21 July 2026 10:50Category: Malware & BotnetsAuthor: IRONQUERY

A newly described intrusion set used Telegram bots for command and control, then layered in obfuscation and environment-bound payloads to make analysis and detection harder.

WebDAV, rundll32, and a Fileless Burglary of Browser and Telegram Secrets

Published: 21 July 2026 10:37Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.

Telegram Turned Into a Silent Relay for a Multi-Stage Government Intrusion Campaign

Published: 21 July 2026 08:12Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A newly examined malware chain shows how attackers can hide command-and-control inside a trusted messaging service while using layered loaders and host-bound checks to slow defenders down.

macOS Infostealer Turns Trusted Sessions Into a Quiet Entry Point

Published: 16 July 2026 13:01Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A reported macOS infostealer shows how stolen sessions, browser secrets, and fake wallet launch paths can move a single endpoint problem into account and crypto risk.

When a Fake Bank Promo Becomes a Phone Hijack

Published: 16 July 2026 12:46Category: Malware & BotnetsGeo: Europe / ItalyAuthor: NEXUSGUARDIAN

A Telegram lure impersonating UniCredit points to a deeper mobile threat: an Android banking trojan built for on-device fraud, not simple password theft.

How a Registry Flag Can Make a Global Shortcut Vanish

Telegram’s t.me links stopped resolving after a .ME registry status change, showing how a public entry point can fail even when the underlying app still works.

When a Single Web Gateway Disappears, Telegram’s Reach Can Shrink Fast

A worldwide t.me suspension shows how a seemingly small naming layer can interrupt browser access, automation, and fast-moving workflows that depend on it.

A Registry Hold Put Telegram’s Short Link Under Pressure

A status change on t.me shows how one domain can sit at the center of a messaging platform’s identity, sharing, and access paths.

One DNS Status Change, Many Broken Doors

A registry-level hold on t.me shows how a single domain action can disrupt Telegram's link ecosystem worldwide while the main app may still be reachable.

Forg365 Turns Microsoft 365 Phishing Into a Bought-and-Sold Access Business

Published: 10 July 2026 18:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.

Fake VPN Lures Are Turning Trust Into a Malware Delivery Channel

Published: 09 July 2026 11:31Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.

One Token, One File, One Hijacked Telegram Session

Published: 06 July 2026 19:44Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A critical flaw in a Telegram-facing MCP server shows how a bearer token can become dangerous when authentication logic is entangled with filesystem-based session handling.

When a Token Becomes a Path: The Telegram Session Bug That Broke the Boundary

A critical flaw in a Telegram MCP gateway shows how a single filesystem mistake can turn bearer-token authentication into an unexpected route into a live account session.

BusySnake Turns One Windows Intrusion Into a Multi-Secret Heist

Published: 04 July 2026 12:08Category: Malware & BotnetsAuthor: IRONQUERY

A Python-based infostealer is being tracked as a focused grab for browser logins, Telegram sessions, screenshots, clipboard data, and crypto material - a reminder that one endpoint can hold many forms of usable trust.

PyPI Poisoning Hits Telegram Bot Builders, and the Backdoor Hides in Plain Sight

Published: 01 July 2026 02:08Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.

Millenium RAT Hides Its Tracks in a Native C++ Build and Telegram-Borne C2

Published: 29 June 2026 10:52Category: Malware & BotnetsAuthor: IRONQUERY

The malware’s latest variant pairs resource-embedded settings with Base64 and XOR obfuscation, making its control plane harder to spot without deeper binary triage.

Millenium RAT v4.* Shifts to Telegram-Controlled Windows Tasking

Published: 29 June 2026 10:41Category: Malware & BotnetsAuthor: IRONQUERY

A Windows remote-access trojan tied to a MaaS model is being linked to Telegram Bot API tasking and a move away from .NET toward native C++ code.

Millenium RAT’s Windows Push Points to a Cleaner, Harder-to-Hunt Malware Model

Published: 29 June 2026 02:05Category: Malware & BotnetsAuthor: SIGNALMONK

Group-IB’s analysis of Millenium RAT v4.* ties 62,289 Windows infections in more than 160 countries to Telegram bot communication, a combination that can blur malicious traffic inside ordinary cloud use.

macOS Malware Finds a Quiet Door in LaunchAgents and a Loud One in AI Triage

Published: 25 June 2026 10:21Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

A Rust-based implant tied to a DPRK-linked macOS cluster pairs ordinary startup persistence with a Python stealer stage and prompt-injection text aimed at analysts.