Nudge is a stalkerware operation identified as Group-549 that was active from March 2016 through November 2019. The operation used Telegram Bot API infrastructure for command-and-control and data delivery, with multiple bots forwarding victim data into a single operator-controlled Telegram chat. Reported webhook usage indicates the operators also relied on secondary web infrastructure alongside Telegram. Nudge is associated with GPS-focused stalking activity and fits the spyware/stalkerware category rather than ransomware or financially motivated cybercrime. Its operational design exposed a personal Telegram user identifier through use of a positive destination chat identifier, indicating direct operator use of a personal Telegram account rather than fully compartmentalized infrastructure. Observed tradecraft includes use of Telegram as an exfiltration and control channel, use of webhooks, and sustained multi-bot campaign management over several years. The available evidence supports describing Nudge as a Telegram-enabled stalkerware campaign, but does not provide high-confidence attribution to a nation state, a specific country of origin, or a defined victim-country set. No additional confirmed aliases or sub-groups are established beyond the Group-549 designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.