Pyrogram-kelra is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Pyrogram-kelra is a malware family tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed June 30, 2026; most recent activity June 30, 2026.
A malware campaign named Operation Navy Ghost has been targeting Python developers creating Telegram bots by distributing trojanized forks of the popular Pyrogram library. Between November 2025 and June 2026, at least…
Pyrogram-kelra is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Pyrogram-kelra on ThreatCluster is dated June 30, 2026.
Across ThreatCluster reporting, Pyrogram-kelra most frequently co-occurs with Malware, Supply Chain Attack, Trojan, Operation Navy Ghost, Kelragram, among 12 tracked related entities.
The most significant recent cluster is “Operation Navy Ghost Targets Telegram Bot Developers with Malicious PyPI Packages” (3 articles · Updated June 30, 2026). Pyrogram-kelra appears across 1 threat cluster in total, listed above with sources.
Pyrogram-kelra appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.