• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Latest Technology News - Telegram has become a new active platform for hackers, and research has found that dozens of malicious viruses are spread through it

Telegram has become a new active platform for hackers, and research has found that dozens of malicious viruses are spread through it

Claire by Claire
April 26, 2021 - Updated on August 4, 2026
in Latest Technology News

As rival WhatsApp has caused controversy over privacy issues, the cloud-based social platform Telegram has become popular this year and has become the most downloaded application in the world during the January 2021 eclipse. It has been installed more than 63 million times and has more than 500 million monthly active users. This popularity also extends to the cybercriminal sector, with more and more malware creators using Telegram as a ready-made command and control (C&C) system.

Telegram has become a new active platform for hackers, and research has found that dozens of malicious viruses are spread through it

As early as 2017, the first use of Telegram as a C&C base system was to steal Masad, and according to security research units Check Point The discussion also summarized the advantages of using popular IM services as a part of the attack:

  • Telegram is a legal, easy-to-use, and stable service that is not blocked by corporate antivirus engines or network management tools
  • Since the registration process only requires entering a mobile phone number, attackers can remain anonymous
  • Telegram’s unique messaging menu makes it easy for attackers to filter data from a victim’s PC or transfer new malicious files to an infected computer
  • Telegram also enables attackers to use their mobile devices to access infected computers from virtually anywhere in the world

In the past three months, Check Point has identified more than 130 attacks using a new versatile remote access Trojan called “Toxic Eye.” The Trojan is delivered via phishing emails containing a malicious .exe and is managed by the attacker via Telegram, communicating with the attacker’s C&C server and passing data to it. As long as the user opens the attachment, Toxic Eye will automatically be installed on the user’s computer and perform a series of exploits without your knowledge, including stealing data, deleting or transferring files, closing processes on the PC, hijacking the computer’s lens and microphone to record videos and audio, encrypting files to demand ransom, etc.

The infection process of Toxic Eye is as follows. The attacker first creates a Telegram account and a Telegram bot. The Telegram bot account is a special remote account. Users can interact through chat or add it to a group, or send requests directly from the input field by typing the Telegram username and query into the program. The bot is embedded in Toxic Eye’s RAT profile and assembled into an executable file. Any victim infected with this malicious virus is at risk of being attacked by a Telegram bot that uses Telegram to connect the user’s device to the attacker’s C&C. Additionally, malicious files displayed in phishing emails can be downloaded and executed by opening them.

If you want to view the complete research report, you can move to Check Point. Here I would like to remind everyone that no platform or tool in the world is absolutely safe. You must stay alert when using it to protect your own safety.

◎Data source:Check Point

 

Source: KOCPC Chinese

Tags: social platformsocial softwareTelegramTrojan horseVirus

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology