New Golang malware leverages Telegram for C2, executing PowerShell commands and self-destructing to evade detection.
Stepasha.exe and MotherRussia.exe payloads raid any ... The data is then exfiltrated to a remote server via Telegram, using hardcoded credentials and bypassing SSL validation to ensure successful ...
A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server.
On Telegram, users are met with so-called identity ... This zip file contains numerous files, including identity-helper.exe [VirusTotal], which a comment on VirusTotal indicates it may be a ...