Telegram API is a tool tracked across 4 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 31, 2025; most recent activity July 23, 2026.
Telegram API is a widely used interface that threat actors leverage for covert command-and-control, data exfiltration, and remote management of malware. Its resilience, ubiquity, and ability to blend with legitimate traffic make it attractive for cyber operations. The provided article notes renewed activity by the Iranian APT 'Prince of Persia' but does not explicitly tie Telegram API to these strains.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems,…
A significant data breach has compromised the personal information of nearly 5 million hotel guests due to vulnerabilities in the Spanish automated check-in service Chekin and the Austrian hotel management software…
The Iranian threat group known as Prince of Persia has re-emerged with three new malware strains targeting critical infrastructure globally. A December 2025 report from SafeBreach revealed that the group, which had been…