#Telegram

Malware/Tool

2019-06-27 • 라자루스(Lazarus) APT 조직, 텔레그램 메신저로 '진실겜.xls' 악성 파일 공격

Telegram is a legitimate messaging platform, not a malware family. BlueNoroff operators hijacked trusted industry accounts to approach senior cryptocurrency and Web3 employees, invite them to fake Zoom or Teams meetings, and deliver Windows or macOS malware through ClickFix instructions. Stolen Telegram sessions could then be reused to contact additional victims. Other DPRK-aligned malware used the Telegram Bot API as command-and-control, including a macOS implant that encrypted payloads with AES-GCM, pinned its TLS certificate, accepted interactive-shell commands, and returned files over Telegram attachments.

Tagged Reports

« Back