PULSE NAME
The Detection & Response Chronicles: Exploring Telegram Abuse
WHITE Lunar_spider PetrP.73 2025-12-17 Modified: 2025-12-17
40
IOCs
MEDIUM VOLUME
Adversaries increasingly exploit messaging applications like Telegram for malicious activities due to its features that support anonymity, resilience, and ease of communication. In recent security assessments from NVISO's Security Operations Center (SOC), four distinct intrusion attempts notably utilizing Telegram have been identified since October 2025, underscoring its role in various cyberattack strategies. Telegram acts as a cloud-based messaging platform that facilitates encrypted communications and supports a robust Bot API. This API is frequently co-opted by threat actors who either hard-code bot tokens or leverage particular channels for command-and-control (C2) functions. The platform's characteristics make it appealing for attackers seeking reliable and anonymous ways to execute operations or communicate with compromised systems.
Indicators of Compromise (4 / 40 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 564b8bb06e8d4be6a6a896a0477aa6af MD5 of ddd2dc2ad3441a762830b2cea99abe5fe1d77fa6abe679a2e8a194505ea7d739 2025-12-17
FileHash-MD5 a424fa182a4b2e99e075716214157f2e MD5 of 5b6e8c0b4ad7b0dde555cadbd9e018c34a7b037f27fa47399c7c107a525cfe4d 2025-12-17
FileHash-MD5 caf1f2f767606ab0be0c7857137a5330 MD5 of f27b20cf5f487636d3c622498ce65ca0057dfd590ffc0c72eac5531a20fb73ce 2025-12-17
FileHash-MD5 ea1b79e4ad6a58619a3e355b5ef4f7d8 MD5 of a7835afd2be9d2b8c770633a8b7fcf635d6a6fb232327bb15dad103bfdf7c058 2025-12-17