Post #4278423
2026-07-31 12:35 UTC
New backdoor TELESHIM runs its command-and-control straight through Telegram. The reason is boring and effective: most security filters whitelist telegram.org, so the traffic just blends in.
That's the trap with allowlists. "Trusted domain" and "safe right now" are not the same thing. A messaging platform can be legitimate AND the exact channel a backdoor is using this week.
We do not blanket-allow telegram.org. We flag it investigate and keep the reason attached: heavily abused for C2. Same domain, honest signal.
https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html
Replies (0)
No replies.