Elektrine lite

← Feed

@reput_io@infosec.exchange

Post #4278423

2026-07-31 12:35 UTC

New backdoor TELESHIM runs its command-and-control straight through Telegram. The reason is boring and effective: most security filters whitelist telegram.org, so the traffic just blends in. That's the trap with allowlists. "Trusted domain" and "safe right now" are not the same thing. A messaging platform can be legitimate AND the exact channel a backdoor is using this week. We do not blanket-allow telegram.org. We flag it investigate and keep the reason attached: heavily abused for C2. Same domain, honest signal. https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html

Replies (0)

No replies.