Telegram Intel Intelligence
Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.
Telegram Intel — Archive & Latest
AI Agent LLMjacking & QR Code Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal active exploitation of AI Model Context Protocol for credential theft and QR code phishing campaigns targeting financial sectors.
M3RX Ransomware Gang: 3 New Victims Posted — Manufacturing & Professional Services Under Siege
M3RX targets Manufacturing and Professional Services in DE, PT, and US. Immediate patching for Check Point and ScreenConnect required.
GoGRPC Backdoor & Teams Vishing Campaign: Helpdesk Hijacker IAB Tactics — OTX Pulse Analysis
Active IAB campaign abusing Microsoft Teams vishing and Quick Assist to deploy GoGRPC backdoor. Critical urgency.
Mirage Kitten Campaign: NightLedger Backdoor & ArcBridge Toolset Analysis
APT group Mirage Kitten targets Middle East & Africa aerospace/defense sectors using NightLedger backdoor and custom malware. Critical urgency.
CastleLoader, NeedleStealer & AI MCP Exploits: Multi-Vector Credential Theft — OTX Pulse Analysis
Active campaigns deploying CastleLoader/NeedleStealer and exploiting AI infrastructure alongside QR-based mobile phishing for credential harvesting.
SAFEPAY Ransomware: DACH Region Blitz — Retail & Education Sectors Under Siege via Critical VPN Flaws
SAFEPAY targets German Retail/Edu sectors using ScreenConnect & VPN exploits. Immediate patching and detection required.
CISA KEV Flash: 8 Critical CVEs Under Active Attack — Fortinet, Check Point & Microsoft Targeted
CISA adds 8 actively exploited CVEs. Critical flaws in Fortinet, Arista, and Microsoft SharePoint allow RCE & auth bypass. Patch immediately.
BabaDeda Loader + ClickFix Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
Advanced BabaDeda loader using ClickFix social engineering targeting enterprise networks. High urgency - widespread detection recommended.
GENESIS Ransomware Gang: 6 New Victims Posted — Critical Infrastructure & Manufacturing Targeted via Firewall Exploits
GENESIS ransomware claims 6 new US/CA victims. Immediate action required on Check Point & Cisco firewall flaws.
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution
Fake Corepack site targeting developers with OpenShield infostealer and Apprunner proxyware via typosquatting. Urgent blocking required.
CRPXO Ransomware: Cross-Sector Surge & Firewall Exploitation — Detection Engineering Brief
CRPXO aggressively targets US Healthcare & Tech sectors via firewall and RMM flaws. Immediate patching of CVE-2026-50751 required.
SECTION9 Ransomware: Surge in LATAM & Global Attacks — Check Point & ScreenConnect Exploitation
SECTION9 claims 15+ new victims targeting Tech, Ag, and Retail. Active exploitation of Check Point and ScreenConnect vulnerabilities observed.
AsyncRAT & Remcos RATs + BabaDeda Loader: Multi-Stage Phishing & ClickFix Campaigns — Enterprise Detection Pack
Active phishing campaigns delivering AsyncRAT/Remcos via steganography and the BabaDeda ClickFix loader. Urgent blocking required.
Langflow AI Pipeline Exploitation (CVE-2026-55255): Chained RCE & IDOR Credential Theft
Active exploitation of Langflow via chained RCE and IDOR vulnerabilities results in credential theft and botnet deployment.
GLOBAL SECRET GROUP: 2026-07-26 Mass Victim Posting — Tech & Finance Sector Targeting via Critical VPN & RMM Exploits
Global Secret Group posts 15 new victims targeting Tech & Finance. Active exploitation of Check Point (CVE-2026-50751) and ScreenConnect (CVE-2024-1708) observed.
TonRAT, AsyncRAT & BabaDeda Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns delivering TonRAT, AsyncRAT, and BabaDeda via ZIPs, phishing, and ClickFix. High urgency for hospitality.
Kimsuky & Void Arachne Surge: KimJongRAT, XenoRAT & DcRAT Campaigns Targeting Asian Infrastructure
Kimsuky & Void Arachne APTs active with KimJongRAT/XenoRAT/DcRAT. Targeting Japan, SK, India via phishing & GitHub abuse. Urgent.
Kimsuky's KimJongRAT & Langflow Exploitation: OTX Pulse Analysis — Enterprise Detection Pack
Kimsuky abuses GitHub for KimJongRAT attacks; Langflow CVEs facilitate credential theft. High urgency.
QILIN Ransomware: 16 New Victims in Global Surge — Education & Healthcare Sectors in Crosshairs as Critical CVEs Exploited
Qilin posts 16 new victims targeting Education, Healthcare, and Gov sectors. Active exploitation of ScreenConnect and Check Point CVEs detected.
Supply Chain Compromise: Klue to LastPass OAuth Token Theft — CRM Data Breach
LastPass CRM data exposed via Klue vendor compromise using stolen OAuth tokens. Urgency: High.
EXFILSQUAD Ransomware: Surge in Critical Infrastructure Targeting — 14 New Victims & CVE Exploitation Analysis
EXFILSQUAD targets US/UK Gov & Tech sectors. 14 victims posted via ScreenConnect and Firewall exploits. Patch immediately.
GitHub Actions Abuse & Supply Chain OAuth Theft: cPanel Exploit & CRM Data Breach
OTX Alert: GitHub Actions abuse powers cPanel exploitation while supply chain OAuth theft exposes LastPass CRM data.
INCRANSOM Ransomware: Cross-Border Healthcare & Legal Sector Targeting — Critical CVE Exploitation
INCRANSOM targets US/CH healthcare and legal firms via VPN/Remote Mgmt exploits. Immediate patching for Check Point & ScreenConnect required.
Y2K Operators: Millenium RAT v4 (C++) Telegram C2 Campaign — OTX Pulse Analysis
Y2K Operators distribute rewritten C++ Millenium RAT v4 via MaaS; abuses Telegram API for C2. High urgency detection guidance.
Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft
Critical OTX pulses reveal CVE-2026-20245 and GitHub Actions abuse targeting enterprise credentials, OAuth tokens, and CRM data.
DEADLOCK Ransomware: Global Manufacturing & Gov Sector Assault — IOCs & Detection Engineering
DEADLOCK gang targets manufacturing & gov sectors via VPN/fw exploits. Immediate defensive actions required.
Prinz Eugen Ransomware: ROOTBOY APT Campaign & Go-based Encryptor — OTX Pulse Analysis
New ROOTBOY Go-ransomware 'Prinz Eugen' targets Finance/Gov via RMM abuse. High urgency. IOCs inside.
Prinz Eugen Ransomware & GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
ROOTBOY deploys Prinz Eugen ransomware; massive GitHub Actions supply chain attack targeting cPanel; LastPass supply chain breach.
MONEYMESSAGE Gang: US Transportation & Energy Under Siege — Critical Firewall & Remote Access Exploitation
MONEYMESSAGE targets US Transportation and Energy sectors using active exploits for Check Point and Cisco vulnerabilities. Immediate patching required.
wp2shell RCE Chain & CMSmap Webshell Deployment: OTX Pulse Analysis — Enterprise Detection Pack
Active exploitation of CVE-2026-63030/CVE-2026-60137 'wp2shell' chain drops CMSmap webshells on default WordPress installs. Urgent.
LokiBot Resurgence & GitHub Actions Supply Chain Attacks: OTX Pulse Analysis
OTX detects active LokiBot credential theft, GitHub Actions abuse for cPanel exploitation, and supply chain OAuth token theft.
KILLSEC Gang: 3 New US/IN Victims — Financial & Healthcare Targeting & Detection Rules
KILLSEC claims 3 new US/IN victims in Finance & Healthcare. Detect specific CVEs and lateral movement TTPs now.
Void Blizzard Zimbra Exploitation + Tycoon2FA Phishing Trends: OTX Pulse Analysis — Enterprise Detection Pack
Void Blizzard exploits CVE-2025-66376 targeting Ukraine; Tycoon2FA phishing shifts to QR codes. Urgency: High.
Hades Implant, AMOS Stealer, and CI/CD Abuse: OTX Pulse Analysis — Credential Theft Campaign
Active campaigns utilizing Hermes AI, AMOS infostealer, and GitHub Actions to harvest credentials via supply chain and cloud exploits.
PLAY Ransomware Campaign: US & Spain Hospitality/Retail Hit — Detection Rules for ScreenConnect & Check Point Exploits
PLAY targets Hospitality/Retail in US/ES exploiting Check Point & ScreenConnect CVEs. Includes IOCs and Sigma detection logic.
ZimReaper, wp2shell, and IOCONTROL: OTX Pulse Analysis — Critical Infrastructure Threat Pack
Active exploitation of Zimbra (CVE-2025-66376) by TA488, widespread wp2shell RCE on WordPress, and Cyber Av3ngers targeting US ICS via IOCONTROL.
Woodgnat Mistic Backdoor & Shai-Hulud NPM Supply Chain Attack: OTX Pulse Analysis
Woodgnat deploys Mistic backdoor & ModeloRAT; Shai-Hulud compromises NPM packages for GitHub token theft. Critical enterprise risk.
Mistic Backdoor, Autonomous AI Agents, and GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns deploying Mistic backdoor and AI-driven Hades implant. High urgency: credential theft and supply chain exploits detected.
FortiBleed, TAG-195 MaaS, & TA458 RoundPress: OTX Pulse Analysis — Enterprise Detection Pack
FortiBleed VPN harvesting, TAG-195 modular MaaS, and TA458 webmail zero-days targeting Gov/Def sectors. Urgency: High.
CyberStrike Harvester & TAG-195 MaaS: Credential Harvesting & AI Supply Chain Attacks — OTX Pulse Analysis
Critical credential theft via FortiBleed and TAG-195 MaaS targets gov/finance. Immediate IOC blocking required.
AKIRA Ransomware: Critical VPN & RMM Exploitation Alert — 4 New Victims
AKIRA targets Manufacturing and Retail via VPN and RMM exploits. Immediate patching of ScreenConnect and Check Point CVEs required.
JadeProx APT: TriBack Loader & Helix Extortion — OTX Pulse Analysis & Detection Pack
JadeProx targets SE Asia with TriBack Loader/PlugX; Helix uses vishing/MFA abuse for extortion. Urgent IOCs and Sigma rules provided.
SectopRAT & StealC: Claude AI Malvertising and Supply Chain CRM Theft
Active malvertising pushes SectopRAT via Claude AI lures; Supply chain breach exposes LastPass CRM data.
NOVA Ransomware: Global Tech Sector Surge & Critical Infrastructure Exploitation
NOVA aggressively targets Technology and Finance sectors via Check Point and Cisco exploits. Immediate patching and IOC hunting required.
NadMesh Botnet Targeting AI Infrastructure: OTX Pulse Analysis — Credential Theft Detection Pack
NadMesh Go-botnet targets AI infra (ComfyUI/Ollama) via Redis exploits to steal credentials. Critical urgency.
TrickBot DNS Tunneling Variant: C2 Infrastructure & Persistence Analysis
Active TrickBot variant detected using DNS tunneling for C2. High urgency due to evasion techniques.
Dolphin X Stealer & Kontraktnik AI-Driven Infostealer Campaign — Enterprise Detection Pack
New Dolphin X stealer targets 300+ apps & SSH keys. Kontraktnik uses AI profiling. Critical for DevOps & Cloud teams.
Dolphin X & Phantom Stealer v3.5: AI-Driven & Multi-Stage Infostealer Campaigns — Enterprise Detection Pack
Dolphin X targets 300+ apps with AI profiling; Phantom Stealer v3.5 phishing Finance/Gov via multi-stage JS payloads. High urgency.
KRYBIT Ransomware Gang: 4 New Victims Posted — Sector Targeting Analysis & Detection Rules
KRYBIT targets Indian Tech & Bulgarian Finance sectors using perimeter exploits. Immediate detection rules included.
Icarus Threat Group: Klue Supply Chain Attack & OAuth Token Theft — Detection Engineering
Active OAuth token theft via Klue supply chain. Icarus targeting CRM data. Critical urgency: immediate token rotation required.
Showing 50 of 891 reports. Archive expands automatically as new intel is generated.
Every Telegram IntelReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.