Telegram Bot - Tool

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
December 31, 2025
Last Seen
June 21, 2026

Telegram Bot is a tool tracked across 12 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed December 31, 2025; most recent activity June 21, 2026.

Overview

Telegram Bot is a cyber threat tool that leverages Telegram's bot API as a covert command-and-control or payload delivery channel. Threat actors use it to issue commands, exfiltrate data, and orchestrate operations from a centralized bot, benefiting from encrypted channels and the platform’s ubiquity. Its significance lies in enabling stealthy, cross-platform control that can evade some traditional network defenses.

Related Threat Clusters

Recent Intelligence Reports

  • Supercomputing on a Credit Card From The AI Rush Enabled The Massive FortiBleed Campaign — Infostealers · June 21, 2026
  • New analysis — www.group-ib.com · June 17, 2026
  • FBI takes down Phishing-as-a-Service platform "Outsider" — Heise.De · June 16, 2026
  • Infosecurity Europe: AI — Infosecurity-Magazine · June 3, 2026
  • A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets — Theregister · May 22, 2026
  • (Source Link) — slowmist.medium.com · May 11, 2026
  • Five Malicious npm Packages Target Crypto Developers, Steal Wallet Keys via Telegram — Gbhackers · March 25, 2026
  • ‘Dead’ Outlook add-in hijacked to phish 4,000 Microsoft Office Store users — Csoonline · February 12, 2026

CVSS v3.1 Breakdown