216.73.216.6

How Adversary Telegram Bots Help to Reveal Threats: Case Study

· Published 21/05/2025 16:50 · Modified 21/05/2025 22:12

Export JSON

Essential information

Published
21/05/2025 16:50
Modified
21/05/2025 22:12
Tags
2025-05-21 cloud platforms credential harvesting exfiltration notion pec phishing telegram
Related entities
16 observables, 9 techniques (mitre), 8 others

Description

This analysis examines a campaign targeting Italian and US users, focusing on for Microsoft services and Italy's system. The attackers use workspaces and other to host pages, exfiltrating stolen data via bots. The campaign, active since 2022, employs simple techniques and off-the-shelf tools, suggesting either low technical expertise or a focus on access brokering. The study demonstrates how intercepting bot communications can aid in profiling threat actors and provides insights into the campaign's evolution, victimology, and attacker characteristics.

External references