Telegram API - Tool

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
December 31, 2025
Last Seen
July 23, 2026

Telegram API is a tool tracked across 4 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 31, 2025; most recent activity July 23, 2026.

Overview

Telegram API is a widely used interface that threat actors leverage for covert command-and-control, data exfiltration, and remote management of malware. Its resilience, ubiquity, and ability to blend with legitimate traffic make it attractive for cyber operations. The provided article notes renewed activity by the Iranian APT 'Prince of Persia' but does not explicitly tie Telegram API to these strains.

Related Threat Clusters

Recent Intelligence Reports

  • T1102 — attack.mitre.org · July 23, 2026
  • Targeted Attack on Middle East Govts (Part 1) — Zscaler · July 21, 2026
  • Targeted Attack on Middle East Govts (Part 1) | ThreatLabz - Zscaler, Inc. — Zscaler · July 20, 2026
  • Spanish, Australian hospitality platform breaches impact nearly 5M | brief — Scworld · April 16, 2026
  • Hackers siphon data from 5M hotel guests, feeding it live onto Telegram — Cybernews · April 15, 2026
  • Iranian APT 'Prince of Persia' is back with three new malware strains — Scworld · December 31, 2025

CVSS v3.1 Breakdown