Raven Stealer is an information-stealing malware family associated with theft and exfiltration of victim data through Telegram. It has been observed collecting data from compromised systems, archiving the stolen material with PowerShell, and using curl to upload the resulting archive to Telegram via the Bot API, specifically the document-upload functionality. This tradecraft reflects a broader trend of commodity stealers and intrusion tooling abusing legitimate cloud and messaging platforms for exfiltration and operational resilience. The malware’s known behavior supports post-compromise collection and exfiltration objectives rather than ransomware or destructive activity. Its use of Telegram provides attackers with a low-cost, easily replaceable communications channel that can blend with legitimate traffic and complicate infrastructure-based disruption. High-confidence reporting directly ties Raven Stealer to data theft and exfiltration over Telegram, but does not establish a specific sponsoring intrusion set, country of origin, or consistent victimology beyond its role as a stealer.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.