Researchers reported multiple malware families abusing Telegram as a command-and-control and exfiltration channel, highlighting how attackers are repurposing the messaging platform’s bot infrastructure for low-cost, resilient operations. Check Point detailed ToxicEye, a multi-function remote access trojan delivered through phishing emails with malicious executables or documents, and said it was observed in more than 130 attacks over a three-month period. Once installed, ToxicEye can steal data, manipulate files, terminate processes, log keystrokes, capture clipboard contents, hijack microphones and cameras, and encrypt files in a ransomware-like manner.
The reporting also linked ToxicEye to a broader pattern that includes Masad Stealer, another malware family using Telegram to move stolen information and receive operator commands. By relying on a legitimate cloud service, attackers can blend malicious traffic with normal user activity, manage infected hosts anonymously through Telegram bots, and even administer campaigns from mobile devices. The cases underscore a continuing shift toward abuse of trusted consumer platforms to simplify malware deployment, remote control, and data theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A blog post published an Android proof-of-concept app, HackContacts2, that reads a device's contacts and exfiltrates them to an attacker-controlled Telegram bot via the Telegram Bot API. The post included implementation details such as required permissions, use of ContactsContract and OkHttp, and noted testing in an emulator, on a real device, and in ANY.RUN where Telegram communication was observed.
A blog post published an Android proof-of-concept that collects device and build information and exfiltrates it to an attacker-controlled Telegram chat via the Telegram Bot API. The sample used OkHttp, stored the bot token and chat ID in local asset files, required only the INTERNET permission, and was reportedly tested on both a virtual device and a real Android 14 OPPO device.
SANS ISC analyzed an Agent Tesla sample delivered in a .daa archive that used the Telegram Bot API for command-and-control and data exfiltration instead of email servers. The analysis identified bot account "Bigdealzbot," recipient chat ID 1599705393, and observed successful uploads of keylogging logs and hourly screenshots.
The Check Point article cites Masad as an earlier info-stealer that used Telegram as command-and-control or exfiltration infrastructure. It places Masad as an early example of malware abusing Telegram for attacker communications.
Check Point publicly documented ToxicEye as a Telegram-based RAT and disclosed its capabilities, delivery methods, detection names, and an indicator of compromise at C:\Users\ToxicEye\rat.exe. The report also highlighted suspicious Telegram traffic from enterprise PCs as a possible sign of compromise.
Check Point Research reported observing more than 130 attacks using the ToxicEye remote access trojan over a three-month period. The malware was delivered via phishing emails and used Telegram bots for command-and-control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourceisc.sans.edu
Open sourceblog.checkpoint.com
Open sourceblogs.juniper.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.