Telegram 2 is a Nim-based macOS persistence implant observed in a June 2025 intrusion investigated by Huntress and attributed with high confidence to the North Korean threat group TA444 / BlueNoroff, also tracked as Sapphire Sleet, COPERNICIUM, STARDUST CHOLLIMA, and CageyChameleon. In the reported campaign, attackers used Telegram-based social engineering, a Calendly lure, a fake Zoom meeting, and deepfake participants to convince a victim at a cryptocurrency foundation to install a malicious AppleScript disguised as a Zoom extension. Telegram 2 was one of eight malicious binaries recovered from the compromised host and served as the persistent binary responsible for starting the primary backdoor and acting as the entry point for the broader malware chain.
The implant was described as disguised as a legitimate Telegram updater. It used the LaunchDaemon path /Library/LaunchDaemons/com.telegram2.update.agent.plist to run /Library/Application Support/Frameworks/Telegram 2, and it created a configuration file at /private/var/tmp/cfg. Reported capabilities include persistence initialization, command execution via echo commands, bash commands, and interactive shell access. One report states the binary was adhoc signed with the identifier root_startup_loader_arm64; another describes it as signed with a valid Telegram developer certificate. The reported SHA-256 for Telegram 2 is 14e9bb6df4906691fc7754cf7906c3470a54475c663bd2514446afad41fa1527.
This malware was deployed alongside other BlueNoroff tooling including the Root Troy V4 Go backdoor, the InjectWithDyld loader, XScreen surveillance malware, and the CryptoBot cryptocurrency infostealer. The overall intrusion targeted a cryptocurrency organization and reflects BlueNoroff's continued focus on financial and cryptocurrency theft using increasingly sophisticated macOS tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Telegram 2 : the persistent binary, written in Nim, responsible for starting the primary backdoor.
Telegram 2 : the persistent binary, written in Nim, responsible for starting the primary backdoor.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The extension turned out to be an AppleScript designed to download a payload and execute a script that disabled bash history logging and checked if Rosetta 2 was installed on the system.
The script begins by disabling bash history logging... Then attempt to get the user’s password and verify it using sudo ... There are several different ways an operator can execute commands on the host using this malware: execShell : run a shell command using /bin/zsh -sc
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nim-based component used to start/initialize the primary backdoor on compromised macOS hosts.
Nim-based persistence implant for macOS, disguised as a Telegram updater, providing initial access and persistence for further malware deployment.
A Nim-based persistent implant that installs a LaunchDaemon, creates configuration data, and can run commands, spawn an interactive shell, and initialize persistence. It serves as the core launcher for other malicious components.
A persistence tool used in the BlueNoroff intrusion chain to maintain access on the victim system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.