Telegram Bot is a tool tracked across 12 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed December 31, 2025; most recent activity June 21, 2026.
Telegram Bot is a cyber threat tool that leverages Telegram's bot API as a covert command-and-control or payload delivery channel. Threat actors use it to issue commands, exfiltrate data, and orchestrate operations from a centralized bot, benefiting from encrypted channels and the platform’s ubiquity. Its significance lies in enabling stealthy, cross-platform control that can evade some traditional network defenses.
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A phishing campaign targeting TRON wallet users has been identified, involving a fake Chrome extension masquerading as the TronLink wallet. This malicious extension employs Unicode bidirectional control characters and…
A modular phishing operation named GitBait has been uncovered, targeting at least 12 Mexican financial institutions over three years. This campaign utilizes GitHub Pages to host fake banking websites, employing a…
The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic…
A Russian-speaking hacker, identified as bandcampro, utilized a jailbroken Google Gemini to execute a cybercrime campaign targeting MAGA supporters from September 2025 to May 2026. The operation involved impersonating…
Five malicious npm packages have been identified that impersonate popular crypto libraries, specifically targeting developers in the Solana and Ethereum ecosystems. These packages, published under the npm account…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
The Iranian threat group known as Prince of Persia has re-emerged with three new malware strains targeting critical infrastructure globally. A December 2025 report from SafeBreach revealed that the group, which had been…
A dormant Microsoft Outlook add-in has been weaponized, leading to the theft of thousands of login credentials and credit card numbers. This incident marks the first known malicious Office add-in discovered in the wild,…
The cyber threat group Amaranth-Dragon has leveraged a critical vulnerability in WinRAR, identified as CVE-2025-8088, to gain persistent control over systems belonging to Southeast Asian governments. This exploitation…