GangExposed RU is a security research persona or group known for publicizing a Telegram client privacy issue involving disguised proxy links. The reported technique used a crafted Telegram proxy link presented as an ordinary username, causing Telegram clients on Android and iOS to test the proxy and thereby expose the user’s real IP address to an attacker-controlled server. The activity attributed to GangExposed RU in this context is vulnerability research and disclosure rather than malicious intrusion, ransomware, or extortion. No high-confidence evidence in the available information supports attribution to a nation-state, criminal intrusion set, or broader offensive campaign, and no corroborated aliases, sub-groups, victimology, or operational targeting are established beyond publication of the technique.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.