Website
api.telegram.org
Tags
C&C Exfiltration
Phishing
None
Command and Control
Telegram is being increasingly used as a C&C server by attackers. CheckPoint reported that a Remote Access Trojan, ToxicEye, used Telegram for C&C. One additional benefit of using Telegram as a C&C server is it allows attackers to use their mobile device to access infected machines.
Exfiltration
Data can be exfiltrated onto Telegram by using a bot controlled by the attacker and sending it the data as a private message. This was demonstrated by SecurityBoulevard.
Download
None
Service Provider
Telegram
Sample
Created: 2021-11-12
Last Update: 2021-11-12
Credits: @abosalahps, @_FirehaK