Researchers uncovered a Pastebin-hosted PowerShell script masquerading as "Windows Telemetry Update" that steals Telegram session data from Windows systems and exfiltrates it through the Telegram Bot API. The malware targets Telegram Desktop tdata files under %APPDATA%, gathers host metadata, terminates Telegram to release file locks, compresses the session material into diag.zip, uploads it to an operator-controlled bot, and then deletes the archive from disk. Analysis identified two versions of the script: an initial broken build that failed to upload stolen archives and a corrected v2 that fixed multipart upload logic, added fallback error handling, and sent a beacon even when Telegram was not installed.
Investigators also tied the same bot infrastructure to a separate browser-based tool designed to capture Telegram Web localStorage authorization data, indicating the operator was developing capabilities to hijack both desktop and web sessions without needing passwords or SMS codes after authentication. Hardcoded bot credentials exposed the attacker’s Telegram bot setup and message history, while a local HTTP collector at 192.168.137.131:5000, cleartext credentials, and the lack of obfuscation or persistence suggested the tooling was still in active testing and validation rather than broad operational deployment.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Flare publicly reported that the Pastebin-hosted PowerShell malware and related web-session capture tool were capable of stealing Telegram session material that could enable session replay without account credentials. The company assessed the activity as tooling under active testing rather than a broadly deployed campaign, citing cleartext credentials, lack of obfuscation or persistence, and private LAN infrastructure.
Analysis of hardcoded bot credentials and message history exposed the operator's Telegram bot infrastructure and revealed a separate browser-based tool that captured Telegram Web session material from localStorage. The web-focused component used the same bot channel and referenced a local HTTP collector at 192.168.137.131:5000.
A second version of the same PowerShell script was later posted under the same Pastebin account, fixing multipart upload logic so stolen Telegram Desktop archives could be sent through the Telegram Bot API. The updated version also added fallback error handling and a beacon even when Telegram was not installed, indicating active validation and development.
Researchers identified an initial Pastebin-hosted PowerShell script disguised as a "Windows Telemetry Update" that targeted Telegram Desktop session data but contained broken upload logic, preventing successful exfiltration. The script still showed intent to collect host metadata and archive Telegram session files from local %APPDATA% paths.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.