HomeSecurityHackers use Telegram as part of malware campaign

Hackers use Telegram as part of malware campaign

According to a new investigation, cybercriminals are exploiting the popular messaging app Telegramby embedding its code in a remote access trojan (RAT) called ToxicEye. A victim's computer infected with the ToxicEye malware is controlled through a Telegram account managed by the hacker.

See also: Hackers abuse Google Forms/Telegram to collect phished credentials

Telegram malware
Hackers use Telegram as part of malware campaign

Researchers at Check Point Software Technologies reported that the ToxicEye malware can take control of file systems, install ransomware , and leak data from the victim's computer.

Check Point said it had detected more than 130 cyberattacks in the past three months that exploited the ToxicEye malware, which was being run by cybercriminals via Telegram. The attackers use the messaging service to communicate with their own server and transfer data to it.

According to researchers, hackers are likely exploiting Telegram as a distribution platform due to its widespread use and popularity, said Idan Sharabi, director of research and development at Check Point.

“We believe that attackers are exploiting the fact that Telegram is used and allowed in almost all organizations. By using this system to carry out cyber attacks, they can bypass security restrictions,” the researcher said.

Hackers use Telegram as part of malware campaign
Hackers use Telegram as part of malware campaign

The researcher points out that Telegram, which is known as a secure and private messaging service, has become even more popular during the pandemic. This also applies to cybercriminals. Malware creators are increasingly using Telegram as a ready-made command and control (C&C) system for their malicious productsbecause it offers many advantages.

Researchers said Telegram is ideal for malicious activity because it is not blocked by antivirus programs and allows attackers to remain anonymous, requiring only a mobile phone number to sign up. The app also allows attackers to take data from victims' computers or transfer new malicious files to infected machines, all of which can be done remotely, from any location in the world.

See also: How to hide your phone number on Telegram

Infection process

Telegram RAT attacks begin with hackers creating a Telegram account and a special Telegram bot that allows them to interact with other users in various ways (chat, adding people to groups, sending requests directly from the input field, by typing the bot's Telegram username and a query).

See also: 100,000 Google sites used to install SolarMarket RAT

The attackers then bundle the bot token with the ToxicEye RAT or other selected malware and distribute the malware via phishing emails with malicious attachments. For example, researchers observed that the attackers distribute the malware via a file called “paypal checker by saint.exe.”

Once a victim opens the malicious attachment, it connects to Telegram and leaves the machine vulnerable to remote attack via the Telegram bot, which uses the messaging service to connect the victim's device to the attackers' command-and-control server. Attackers gain full control of the victim's machine and can perform other malicious activities.

According to Check Point's observations, ToxicEye malware is used to detect and steal passwords, computer information, browser history, and cookies from people's devices. It can also delete and move files, terminate processes, and steal content from the clipboard. Finally, it acts as a keylogger, records audio and video, and encrypts files.

ToxicEye malware
Hackers use Telegram as part of malware campaign

Detection and protection

Check Point said that one indication of infection is the presence of a file called “rat.exe” located in the directory C:\Users\ToxicEye\rat[.]exe.

Organizations should also monitor traffic between PCs and Telegram accounts when the Telegram app is not installed on those systems. Finally, the researchers recommend being very careful with emails , especially attachments.

Source: Threatpost

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS