Dark Side Intelligence Category

Telegram Intel Intelligence

Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.

1171 reports availableRefreshed every 5 minutes

Telegram Intel — Archive & Latest

50 reports loaded
Telegram Intel

KRYBIT Ransomware Gang: 5 New Victims Posted — Healthcare and Education Targeting With Perimeter-Edge CVE Pressure

KRYBIT posted 5 new victims across healthcare, professional services, education and agri-food; defenders should prioritize edge-VPN, ScreenConnect, Exchange and pre-encryption staging hunts.

Sep 6, 2026
Read →
Telegram Intel

PANZER Ransomware: 4 Victims Posted in 72 Hours — European & Middle East Targeting, Sector Analysis & Detection Rules

PANZER posted 4 victims in 72 hours across Saudi Arabia, Germany, and Indonesia, hitting government, education, and professional services. Detection rules and IR priorities inside.

Sep 6, 2026
Read →
Telegram Intel

Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack

Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.

Sep 6, 2026
Read →
Telegram Intel

UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack

UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.

Sep 6, 2026
Read →
Telegram Intel

THEGENTLEMEN Ransomware Gang: 5 Victims in 5 Days — Transportation, Healthcare & Technology Under Active Fire

THEGENTLEMEN posted 5 victims across 4 countries in 5 days, hitting Transportation, Healthcare, Retail, and Tech. Enterprises with exposed VPNs, RDP, or unpatched KEV flaws should hunt now.

Sep 5, 2026
Read →
Telegram Intel

MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack

MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.

Sep 5, 2026
Read →
Telegram Intel

MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack

MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.

Sep 5, 2026
Read →
Telegram Intel

DIREWOLF Ransomware: 6 Victims in 5 Days — Cross-Sector Campaign Hits US Tech, Thai Energy, and Global Manufacturing

DIREWOLF posted 6 victims in 5 days spanning tech, energy, transportation, and manufacturing across US, ZA, TH, BR, ID. Edge-VPN and remote access exploitation suspected. Patch and hunt now.

Sep 5, 2026
Read →
Telegram Intel

SPACEBEARS Ransomware Gang: 3 Fresh Leak-Site Victims — US/IT Sector Pressure, KEV Edge Exposure & Pre-Encryption Hunt Rules

SPACEBEARS posted 3 US/IT victims across retail, professional services and healthcare; patch KEV edge/RMM flaws and hunt pre-encryption staging now.

Sep 4, 2026
Read →
Telegram Intel

FDMTP Implant via QuickFox Supply Chain Attack + ENDLESSDOORS Router Backdoor (CVE-2026-66747): OTX Detection Pack

Two supply chain campaigns exposed: trojanized QuickFox VPN installers deploying the FDMTP implant, and Zbtlink routers shipping with the pre-installed ENDLESSDOORS backdoor (CVE-2026-66747).

Sep 4, 2026
Read →
Telegram Intel

VEXY Ransomware Gang: 5 New Victims in 4 Days — India & LATAM Campaign, Sector Analysis & Detection Rules

VEXY Ransomware posted 5 victims in 4 days spanning manufacturing, retail, and hospitality across India, Ecuador, and Brazil. Edge-VPN CVEs flagged as likely entry vectors.

Sep 4, 2026
Read →
Telegram Intel

TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack

TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.

Sep 4, 2026
Read →
Telegram Intel

QILIN Ransomware Gang: 7 Victims in 5 Days — Government, Energy & Manufacturing Targeting with Detection Rules

Qilin (Agenda) posted 7 victims in 5 days across CA, US, CL, TR, AR — hitting government, energy co-ops, and manufacturing. KEV-linked edge exploitation suspected; detection rules included.

Sep 4, 2026
Read →
Telegram Intel

SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack

Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.

Sep 4, 2026
Read →
Telegram Intel

STORM Ransomware Gang: 8 New Victims in 72 Hours — Energy, Financial & Healthcare Targeting Analysis with Detection Rules

STORM posted 8 victims across CA, US, and AU in 72 hours, hitting energy, financial services, transportation, agriculture, and healthcare. Detection rules and IR priorities inside.

Sep 4, 2026
Read →
Telegram Intel

Microsoft Teams Help-Desk Vishing + RMM Lateral Movement: OTX Pulse Detection Pack

OTX flags Teams help-desk impersonation leading to malware execution and lateral movement; 8 IPv4 C2/RMM indicators. Enterprise SOC urgency: high.

Sep 3, 2026
Read →
Telegram Intel

The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack

The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.

Sep 3, 2026
Read →
Telegram Intel

The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack

OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.

Sep 3, 2026
Read →
Telegram Intel

INCRANSOM Ransomware Gang: 11 New Victims in 5 Days — Manufacturing & Healthcare Surge, Detection Rules Inside

INCRANSOM posted 11 victims across 8 countries since Aug 31, hitting manufacturing, healthcare, education and financial services. Detection rules and hunt queries included.

Sep 3, 2026
Read →
Telegram Intel

ScreenConnect RMM Abuse + SockTz AI-Enabled Intrusions + Teams Help Desk Vishing: OTX Pulse Analysis — Enterprise Detection Pack

Multi-wave campaigns abuse ScreenConnect RMM, Cloudflare tunnels, AI tooling, and Teams vishing against LATAM and enterprise orgs. Detection pack included. Hunt immediately.

Sep 3, 2026
Read →
Telegram Intel

Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack

Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.

Sep 3, 2026
Read →
Telegram Intel

Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack

Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.

Sep 3, 2026
Read →
Telegram Intel

SILENTRANSOMGROUP Ransomware Campaign: 4 Victims Posted in 48 Hours — BigLaw Targeting Analysis, Detection Rules & Hunting Queries

SILENTRANSOMGROUP posted 4 victims in 48 hours, including major US law firms Greenberg Traurig and Holland & Knight. Professional services orgs must act now.

Sep 3, 2026
Read →
Telegram Intel

D2IP C2 Evasion + Rogue ScreenConnect Worm Activity + Teams Help Desk Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal 45% of malware bypassing DNS via direct-to-IP C2, worm-like rogue ScreenConnect RMM deployments dropping XMRig, and Teams help desk vishing. High urgency for education, government, and transportation sectors.

Sep 3, 2026
Read →
Telegram Intel

Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack

Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.

Sep 3, 2026
Read →
Telegram Intel

Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack

Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.

Sep 3, 2026
Read →
Telegram Intel

AKIRA Ransomware Gang: 9 New Victims in 72 Hours — Sector Targeting Analysis, CVE Correlation & Detection Rules

AKIRA posted 9 victims in 72 hours spanning manufacturing, financial services, retail and transportation across the US, NL and DE. Detection rules and IR priorities inside.

Sep 3, 2026
Read →
Telegram Intel

Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack

CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.

Sep 2, 2026
Read →
Telegram Intel

Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack

OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.

Sep 2, 2026
Read →
Telegram Intel

LOCKBIT5 Ransomware Gang: 6 Victims Posted in 24 Hours — Financial Services & Manufacturing Targeting Analysis with Detection Rules

LOCKBIT5 posted 6 victims across US, JP, and NL on 2026-08-31, hitting financial services, legal, and manufacturing firms. Detection rules and IR priorities inside.

Sep 2, 2026
Read →
Telegram Intel

Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack

OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.

Sep 2, 2026
Read →
Telegram Intel

Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack

OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.

Sep 2, 2026
Read →
Telegram Intel

XCSSET v40 Supply Chain Surge + SakDriver Kernel Rootkit + Teams Help Desk Intrusion: OTX Detection Pack

OTX pulses reveal XCSSET v40 infecting Xcode dev environments, the SakDriver Ring-0 rootkit evading ETW, and Teams-based help desk intrusion with live C2. High urgency — hunt now.

Sep 2, 2026
Read →
Telegram Intel

Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack

OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.

Sep 2, 2026
Read →
Telegram Intel

CISA KEV Flash: 11 CVEs Added — PaperCut, Citrix NetScaler & Linux Kernel Under Active Exploitation

CISA confirms active exploitation of 11 CVEs incl. PaperCut NG/MF, Citrix NetScaler, Linux Kernel, JFrog Artifactory & ownCloud. Patch now — federal deadlines apply.

Sep 1, 2026
Read →
Telegram Intel

Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack

Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.

Sep 1, 2026
Read →
Telegram Intel

Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis

13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.

Sep 1, 2026
Read →
Telegram Intel

KRYBIT Ransomware Gang: 14 Victims Posted in Single-Day Surge — Cross-Sector Campaign Analysis & Detection Engineering

KRYBIT posted 14 victims in 24 hours spanning healthcare, education, tech, and transport across 9 countries. Detection rules, KQL hunts, and IR priorities inside.

Sep 1, 2026
Read →
Telegram Intel

BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack

OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.

Sep 1, 2026
Read →
Telegram Intel

OROVA Ransomware Gang: 4 New Victims Posted — APAC Technology, Manufacturing & Hospitality Targeting Analysis & Detection Rules

OROVA posted 4 new victims to its leak site this week, concentrated in Taiwan and Hong Kong across Technology, Manufacturing, and Hospitality. VPN-edge exploitation and double extortion remain the gang's primary playbook.

Sep 1, 2026
Read →
Telegram Intel

EtherHiding Magecart Campaign: Blockchain-Staged Card Skimmers Targeting WooCommerce & Magento — OTX Detection Pack

OTX pulse reveals Magecart operators staging payment skimmers inside Ethereum smart contracts, compromising WooCommerce, PrestaShop and Magento storefronts. High urgency for retail/e-commerce defenders.

Aug 31, 2026
Read →
Telegram Intel

BRAINCIPHER Ransomware Gang: 4 New Victims in 24 Hours — Cross-Sector Campaign Analysis & Detection Rules

BRAINCIPHER posted 4 victims across AE, DE, and US on 2026-08-31, spanning healthcare, technology, and professional services. Edge-VPN patching and pre-encryption staging hunts are urgent.

Aug 31, 2026
Read →
Telegram Intel

Spring Ring Teams Vishing + EtherHiding Magecart + Gryxa AI-Built Toolkit: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal Teams-based vishing (Spring Ring), blockchain-staged Magecart skimmers, and the AI-built Gryxa RMM toolkit. Retail & enterprise targets. High urgency.

Aug 31, 2026
Read →
Telegram Intel

ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack

Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.

Aug 31, 2026
Read →
Telegram Intel

JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack

OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.

Aug 31, 2026
Read →
Telegram Intel

WALLSTREET Ransomware: US Healthcare and Education Victims Posted — Leak-Site Signals, CVE Access Paths & Detection Rules

WALLSTREET posted Cedar County Memorial Hospital and Andover; US healthcare and education teams should harden VPN, Exchange, RMM and link-following paths now.

Aug 31, 2026
Read →
Telegram Intel

Fake MP4 ISO-BMFF Trojan + NetSupport RAT: PowerShell Loader Campaign via Cloudflare Infrastructure — OTX Detection Pack

Active campaign hides encrypted NetSupport Manager RAT inside fake MP4 uuid boxes, delivered via Cloudflare-fronted PowerShell loaders. High urgency — deploy IOCs & hunts now.

Aug 31, 2026
Read →
Telegram Intel

Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.

Aug 31, 2026
Read →
Telegram Intel

Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack

OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.

Aug 31, 2026
Read →
Telegram Intel

CHAOS Ransomware Gang: 3 Victims Posted in 48 Hours — US/GB/AU Targeting, KEV-Linked Access Paths & Detection Rules

CHAOS posted corematerials.com, macallister.com and singleton.com within 48h. Manufacturing and unclassified GB/AU firms should harden VPN/RDP/RMM paths now.

Aug 31, 2026
Read →

Showing 50 of 1171 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Telegram IntelReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.