TeleBots is a malware/threat cluster described by ESET as a successor to BlackEnergy and associated with the Sandworm activity set, which the cited content links to Russia’s GRU Unit 74455. It was observed targeting financial institutions in Ukraine and is noted as a subgroup that launched multiple destructive operations, most notably the 2017 NotPetya outbreak. TeleBots abused the Telegram Bot API so attacker communications resembled normal HTTP(S) traffic to api.telegram.org. ESET reported TeleBots deploying destructive KillDisk variants, including fake-ransomware functionality affecting both Windows and Linux systems. These variants replaced files with strings such as "mrR0b07" and "fS0cie7y," and on Linux displayed a 222 Bitcoin ransom demand; the Linux encryption scheme reportedly contained a deliberate flaw that prevented decryption even if victims paid. The content also states that ESET attributed NotPetya to TeleBots at the time, with initial distribution via a compromised update mechanism for the Ukrainian accounting software M.E.Doc and subsequent worm-like propagation using the SMB exploits EternalBlue and EternalRomance. Additional linkage in the content includes ESET’s assessment that the Exaramel backdoor was used by TeleBots and shared similarities with Industroyer, including use of the domain um10eset[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.