Scopper is a Telegram-based remote access trojan (RAT) library used in malicious Python packages rather than a standalone RAT. Safety researchers identified it while investigating the PyPI supply-chain campaigns dubbed “Telegrem” / “Telegrem-Bot,” which used seven malicious typosquatted packages including telegrem, telegreph, aiogrem, rendom, pyrogrem, pyrogrqm, and pyrogrom to target Python developers. In this campaign, Scopper provided Telegram-controlled RAT functionality within a multi-stage infection chain.
The reported infection flow used malicious PyPI packages as the initial vector, with telegrem typosquatting the legitimate telegram package. A later stage masqueraded as an Islamic prayer-times/Quran Telegram bot while covertly downloading and executing additional Python code from Pastebin using obfuscated URL reconstruction and Python InteractiveInterpreter. Another loader stage fetched the main payload from i7trak-id3i.onrender.com and reported execution status to the attacker via Telegram.
The main RAT payload associated with this activity supported interactive shell command execution, directory navigation, file browsing, file exfiltration including bulk collection and zipping, recursive filesystem scanning for targeted extensions such as .py, .json, and .txt, SSH backdoor installation by adding an attacker public key and enabling OpenSSH/port 22, Telegram bot token theft using regex-based discovery and Telegram API validation, and Android/mobile data theft from paths such as /storage/emulated/0/DCIM and /sdcard/Pictures. It also auto-installed dependencies including telebot, chardet, requests, and pexpect, stored mode state in current_mode.txt, tracked exfiltrated files in sent_files.log, and included auto-restart behavior. An optional additional payload could be fetched from Pastebin via a RAT command, but its purpose was still unknown in the cited reporting.
High-confidence IOCs directly mentioned in the reporting include Pastebin URLs https://pastebin.com/raw/M3Rh68JJ and https://pastebin.com/raw/QASyStax, the Render-hosted domain https://i7trak-id3i.onrender.com, Telegram bot tokens 8107850370:AAE1Mm-MrvA1ku4E6uZd-X_pBKrguPiYRhA, 7573350100:AAGhDJC1dsAKym8myLFARlCCzna-bfRciBo, and 7104475220:AAEqHSMFzR542VyuCZqw9HBx-DTCnTe8ImI, attacker chat IDs 7889168418 and 1896077619, and an attacker SSH public key labeled “u0_a268@localhost.” Safety reported coordinating with the PyPI security team to remove the Scopper package.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python library used by malicious packages to provide Telegram-controlled remote access trojan (RAT) functionality; it is embedded as a component rather than operating as a standalone implant.
A Python-based Telegram-controlled RAT capability delivered as a reusable library intended to be imported by other malicious PyPI packages; provides Telegram C2-driven remote administration features when embedded by downstream packages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.