Researchers find Telegram bot chatter is actually Windows malware commands
#1
Quote:Decrypted Telegram bot chatter was found to actually be a new Windows malware, dubbed GoodSender, which uses the messenger platform to listen and wait for commands.

Forcepoint researchers discovered what it described as a “fairly simple” year old malware that creates a new administrator account that enables remote desktop once it infects a victim’s device.

The attacker then uses Telegram to communicate with the malware and send HTTPS protected instructions.

The malware also revealed a vulnerability in Telegrams BOT API. Because the messages were sent by Telegram Bot API, and not between regular users, anyone knowing a few key pieces of information can snoop on the bot chatter and even recover full messaging histories of the target bot. Regular user’s messages are also protected with in-house MTProto encryption.

Source: https://www.scmagazine.com/home/security...-commands/

Report by Forcepoint: https://www.forcepoint.com/blog/security...egram-bots
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WhatsApp Adds Security Warning Before Us...
WhatsApp has intro...harlan4096 — 08:21
uBOLite 2026.625.1633
uBOLite 2026.625.1...harlan4096 — 07:35
7-Zip 26.02
7-Zip 26.02 Wha...harlan4096 — 07:23
AMD to bring back Ryzen 7 5800X3D as AM...
AMD has officially r...harlan4096 — 07:12
Windows Secure Boot Certificate Expiry E...
Microsoft’s long-p...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>