Skip to content
Fake Telegram Download Site Distributes Stealthy Malware

Fake Telegram Download Site Distributes Stealthy Malware

First seen 18 Mar 2026, 11:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 19, 2026 at 11:13 UTC
  • •A fake Telegram download site is distributing malware via a typosquatted domain.
  • •The malicious installer masquerades as a legitimate setup file for Telegram.
  • •Users are advised to avoid downloading software from unofficial sources.

A new malware campaign is targeting Telegram users through a typosquatted website, telegrgam[.]com, which closely resembles the official Telegram download portal. The site offers a trojanized installer named tsetup-x64.6.exe, tricking users into downloading malicious software. Once executed, the installer initiates a multi-stage attack chain, compromising affected systems. This campaign exploits user trust and could potentially impact a large number of Telegram users who mistakenly visit the fraudulent site. The attack method relies on social engineering tactics to deceive users into downloading the malware. Currently, there are no specific numbers on the number of affected users or systems. Security experts are advising caution when downloading software from unofficial sources. The situation is ongoing as the malicious site remains active.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2026-03-18
Malware campaign reported exploiting typosquatted Telegram site.

More articles in this cluster (2)