threat-intel Armored Likho expands its cyber-espionage toolkit The Armored Likho group (also known as Eagle Werewolf) has significantly expanded its cyber-espionage toolkit with the introduction of the ‘Still Toolkit,’ a new set of tools designed for advanced surveillance and data theft. The toolkit includes Still Sync, a Stealer for Telegram session data, and Still Audio, an audi… Securelist · Aug 13, 2026 High RUcyber espionagetelegramaudio surveillance
threat-intel Russian businesses erase Durov-linked products after 'terrorist' designation Following Russia's designation of Telegram founder Pavel Durov as a terrorist and extremist, numerous Russian businesses are removing products associated with him, including books, films, and merchandise. Despite these e… The Record · Aug 4, 2026 High RUFRUAcensorshipduraovtelegram
threat-intel Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks A Chinese-speaking threat actor, tracked as ‘KnYuan’ and ‘Knaithe’, utilized the Hermes Agent framework and DeepSeek to autonomously launch attacks against over 460 targets. The agent, leveraging Telegram, identified and… The Hacker News · Jul 31, 2026 High CVE-2026-3055CVE-2026-39987CVE-2026-33017CHautonomous attacksvulnerability exploitationtelegram
threat-intel The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version The XCSSET malware family has returned with version 40, exhibiting enhanced stealth and persistence techniques to evade detection and compromise macOS systems, particularly those of software developers. This latest itera… Palo Alto Unit 42 · Jul 31, 2026 High SOmacossupply chainmalware
threat-intel 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China A sophisticated, full-service mobile malware-as-a-service (MaaS) framework called ‘Flying Eagle’ has emerged from the Chinese cybercriminal underground, enabling criminals to build and deploy mobile malware campaigns wit… Dark Reading · Jul 30, 2026 High CHmaasmobile malwarecybercrime
threat-intel Russia accuses Telegram founder of aiding terrorism, seeks international arrest Russia has formally accused Telegram founder Pavel Durov of aiding terrorism, seeking an international arrest warrant due to allegations that the messaging app was used by Ukrainian intelligence to organize terrorist att… The Record · Jul 29, 2026 High RUUKFRrussiatelegramukraine
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
threat-intel TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments A threat actor linked to East Asia has been targeting government entities in the Middle East using a sophisticated attack chain leveraging Telegram for command-and-control. The campaign utilizes malware families like TEL… The Hacker News · Jul 27, 2026 High CNedr evasiontelegramcommand and control
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach Russian journalist Ksenia Sobchak's Telegram channels were briefly taken over by hackers who published alleged private correspondence. The hackers, operating under the group Black Mirror, claimed to have stolen over 350G… The Record · Jul 13, 2026 Medium RUUKtelegramdata breachrussian
threat-intel Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Iran's cyber operations, primarily conducted through groups like Handala and Ababil of Minab, are increasingly targeting a broader range of organizations beyond critical infrastructure. These groups, often described as h… Dark Reading · Jul 9, 2026 Medium CVE-2021-22681IRhacktivismcyber espionagevulnerability exploitation
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
threat-intel Google Is Suing Chinese Scammers Who Are Using Gemini Google is taking legal action against a Chinese group, Outsider Enterprise, who were leveraging Google's Gemini AI to create sophisticated phishing campaigns. The group utilized Telegram to offer ‘phishing-as-a-service,’… Schneier on Security · Jul 7, 2026 Medium CNphishingaigemini
threat-intel New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A new macOS malware, dubbed Gaslight, has been discovered using prompt injection techniques to deceive AI-powered analysis tools. Developed by North Korea-aligned threat actors, the malware steals information and attempt… The Hacker News · Jun 25, 2026 High KPmacosprompt injectionai evasion
threat-intel Telegram admits it couldn't police exam-leak channels, India tells court India's government blocked Telegram access following reports of leaked exam materials for the NEET-UG 2026 medical entrance exam, leading to disruptions for users globally. Telegram initially admitted limitations in proa… BleepingComputer · Jun 18, 2026 Medium INAEexamleakregulatory
threat-intel India temporarily blocks Telegram over medical exam cheating fears India temporarily blocked access to the Telegram messaging app due to concerns about cheating during a nationwide rerun of the NEET-UG medical entrance exam. Authorities cited instances of scammers using Telegram to dist… The Record · Jun 16, 2026 Medium INtelegramexamcheating
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability