pip install teligram

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
pip install teligram 🧐 (better not run it)
On February 8, the teligram library was published.
Its description reads: Telegram-based friendly library.
Alas, as usual in our posts, there are no miracles — the library is a custom Remote Access Tool (RAT).
Its features:
• Traces of LLM usage are present.
• Contains one large function khelo, which implements 16 sub-functions.
• Traces of the Indian language are present (khelo translates to “play”; the chosen developer name Om Devendra is Indian).
• The code is not obfuscated, and the bot’s greeting sent when using the /help and /start commands by an administrator reflects the capabilities:
Available commands:
pwd - Show current directory
ls or ls -la - List files
cd <directory> - Change directory
whoami - Show current user
date - Show date and time
TAKE COMMANDS:
1. take <number> - Get the nth file
Example: take 1
2. take <file_name> - Get file by name
Example: take myfile.txt
3. take .<extension> - Get all files with extension
Example: take .jpg or take .py
4. take all - Get ALL non-empty files
5. /send - Upload files to current directory
Special features:
- Working directory saved between commands
- Empty files automatically skipped
Version 1.0.0 does not have post-install launch functionality. The other versions did not have time to be released — the package was sent to quarantine, although it existed for 19 hours.
💬 By the way, you can now read ESCalator on MAX as well. And this is not a scam.
#pypi #ti #scs #pyanalysis
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



