#Telegram

Malware/Tool

2023-12-06 • Analysis of North Korean Hackers’ Targeted Phishing Scams on Telegram

Telegram is a legitimate messaging platform, not a malware family. BlueNoroff operators hijacked trusted industry accounts to approach senior cryptocurrency and Web3 employees, invite them to fake Zoom or Teams meetings, and deliver Windows or macOS malware through ClickFix instructions. Stolen Telegram sessions could then be reused to contact additional victims. Other DPRK-aligned malware used the Telegram Bot API as command-and-control, including a macOS implant that encrypted payloads with AES-GCM, pinned its TLS certificate, accepted interactive-shell commands, and returned files over Telegram attachments.

Tagged Reports

« Back