Telegram Intel Intelligence
Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.
Telegram Intel — Archive & Latest
Moobot/Mirai Botnet Resurgence: Open Directory Exposure of 'StresD Pro+' DDoS-as-a-Service Panel — OTX Pulse Analysis & Detection Pack
OTX pulse reveals exposed Moobot source code and active 'StresD Pro+' DDoS panel post-2024 takedown. IoT botnet ops tied to China-linked infrastructure. High urgency.
DARKLANTERN, SPEAKINGSTONE & ENDLESSDOORS: ZBT Router Firmware Implants in the Global Supply Chain — OTX Pulse Analysis & Detection Pack
Three firmware implants embedded in ZBT routers expose root shell access via unauthenticated UDP 9992 backdoor. Global supply chain reach across 11 countries. Critical urgency.
BARRACUDA Ransomware Gang: 3 New Leak-Site Listings — Sector Targeting Analysis, Detection Rules & Response Playbook
BARRACUDA listed 3 organizations on its dark web leak site this week — manufacturing and services firms, with Argentina in scope. Unverified claims; detection rules inside.
CISA KEV Flash: 10 CVEs Added — MikroTik, Microsoft SharePoint, F5 & Check Point Under Active Attack
CISA confirms active exploitation of 10 new CVEs spanning MikroTik, SharePoint, WordPress, F5 BIG-IP, Check Point, Zyxel & more. Federal deadlines binding. Patch now.
THEGENTLEMEN Ransomware Gang: 4 New Leak-Site Claims — Sector Targeting Analysis & Detection Engineering
THEGENTLEMEN has listed 4 new organizations on its dark web leak site spanning Technology, Manufacturing, and Retail across US, SG, and PT. All listings are single-source, unverified claims.
AKIRA Ransomware Gang: 5 New Victim Claims Posted — Manufacturing & Professional Services Listing Analysis With Detection Rules
AKIRA's leak site added 5 new claimed victims in 72 hours, concentrated in US manufacturing and professional services. Unverified claims — but the exposure signals are actionable now.
TERMITE Ransomware Gang: 4 New Leak-Site Listings in 4 Days — US-Only Targeting, Sector Analysis & Detection Rules
TERMITE listed 4 US organizations on its leak site between 2026-09-22 and 2026-09-25 — all single-source claims spanning manufacturing, financial services, and real estate. Unverified; defenders should treat as exposure signal.
Salt Typhoon / Fire Ant TACACS+ Pre-Auth RCE (CVE-2026-48842): OTX Pulse Analysis — Telecom Infrastructure Detection Pack
OTX flags critical pre-auth RCE in TACACS+ (CVE-2026-48842) tied to Salt Typhoon/Fire Ant telecom espionage. Pre-authentication exploitation of network AAA. URGENT.
AnonyMousKIT AI-Powered PhaaS Supply Chain: 506-Domain Apple Activation Lock Phishing Network — OTX Detection Pack
OTX exposes AnonyMousKIT, an AI-driven PhaaS with 506 domains harvesting Apple ID credentials via SMS, WhatsApp, email & vishing. Gov/Edu targeted. HIGH urgency.
EVEREST Ransomware Gang: 6 New Leak-Site Listings Posted — Sector Targeting Analysis & Detection Rules
EVEREST listed six organizations across professional services, healthcare, technology and education; defenders in SE, ZA, JP and BE should hunt pre-encryption staging now.
OpenSUpdater SFX Evasion, Sliver C2 Against Philippine Nuclear/Defense, and SilentXMRMiner On-Endpoint Compilation: OTX Pulse Analysis — Enterprise Detection Pack
Three active campaigns: OpenSUpdater hidden in recompiled 7zip SFX, Chinese-speaking APT exfiltrating 9GB from Philippine nuclear/defense targets, and silent Monero miners compiled directly on endpoints. High urgency.
ClickFix Clipboard Poisoning via third-party.com, Galago Ransomware Emergence, and TACACS+ Pre-Auth RCE: OTX Pulse Analysis — Enterprise Detection Pack
ClickFix lures hijack placeholder domain third-party.com; Galago ransomware hits Icelandic healthcare; critical pre-auth RCE in TACACS+ protocol. Hunt now.
WALLSTREET Ransomware Gang: 7 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
WALLSTREET listed 7 organizations across manufacturing, energy, finance, healthcare, legal, and education in GB/US/SV. Unverified claims; defenders should hunt pre-ransom TTPs now.
Dark Caracal GoCaracal Framework + Russian Evilginx OAuth Phishing Clusters: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal Dark Caracal's new GoCaracal modular espionage framework targeting Latin America and Russian clusters (UNC6293/UNC7005/UNC5976) running Evilginx OAuth/device-code phishing against academia and government. High urgency — credential theft at scale.
INCRANSOM: 6 New Leak-Site Listings — Healthcare and Professional Services Claims, Exposure Analysis & Detection Rules
INCRANSOM listed six organizations across healthcare, professional services, and manufacturing; defenders should prioritize access, staging, and exfiltration controls.
RemotePanel + BoundSiphon: ClickFix-Delivered Dual-Payload Toolkit for Persistent Access & Browser Credential Theft — OTX Detection Pack
OTX pulse details two undocumented .NET payloads — RemotePanel HVNC RAT and BoundSiphon browser stealer — deployed via ClickFix chains with blockchain-based C2 resolution. Immediate credential rotation advised.
N0N Ransomware Gang: 3 Leak-Site Listings Across Technology and Retail — Detection Rules & Sector Exposure
N0N lists 3 orgs across US, ML, and UZ technology and retail; all are single-source claims. Technology, retail, and IT services teams should hunt remote-access and staging indicators.
HookBot Android Banking Trojan Leak, ClickFix Clipboard Poisoning & Konni VelvetCake LNK Campaign: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose leaked HookBot/ERMAC panels with default creds, ClickFix lures on third-party[.]com, and Konni's VelvetCake LNK campaign targeting Ukraine. Hunt now.
MacSync macOS Stealer + HookBot/ERMAC Android Banking Leak: OTX Pulse Analysis — Credential-Theft Detection Pack
OTX flags MacSync targeting macOS crypto users/devs and HookBot/ERMAC source leak enabling Android banking panel sprawl. Hunt now; credential exposure likely.
ENDZONE Ransomware Gang: 3 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
ENDZONE has listed 3 organizations on its leak site in the past 5 days, concentrated in US professional services and technology. Unverified claims — defenders should hunt now.
DRAGONFORCE Ransomware Gang: 4 New Victims Listed — Cross-Regional Campaign Analysis & Detection Engineering
DRAGONFORCE listed 4 new victims across TW, TH, FR, and US on its leak site, spanning manufacturing, healthcare, and other sectors. Unverified claims — defenders should hunt now.
PavinLoader Multi-Stage Campaign: ClickFix, Fake Captchas & EtherHiding Blockchain C2 — OTX Pulse Analysis with Enterprise Detection Pack
PavinLoader .NET loader distributing Amatera Stealer & HijackLoader via ClickFix/fake captcha lures, using MSBuild abuse and EtherHiding blockchain C2. High urgency.
CARBONATO Docker Botnet + PavinLoader/Amatera Stealer: OTX Pulse Analysis — Exposed Daemon Exploitation & ClickFix Credential Theft Detection Pack
OTX pulses reveal CARBONATO botnet abusing exposed Docker daemons and PavinLoader delivering Amatera Stealer via ClickFix. Credential theft focus. High urgency.
EMPERADOR Ransomware Gang: 6 New Leak-Site Listings Across Government, Healthcare & Transportation — Analysis & Detection Rules
EMPERADOR has listed 6 organizations on its dark web leak site, spanning government, healthcare, transportation, and manufacturing. Unverified claims — defensive guidance inside.
SILENTRANSOMGROUP: 6 New Leak-Site Listings Claimed — Legal & Professional Services Targeting Analysis and Detection Engineering
SILENTRANSOMGROUP has listed 6 organizations — including several US professional services / legal firms — on its dark web leak site. Claims are unverified; legal and professional services teams should hunt now.
DPRK Hangro State VPN Infrastructure Exposed: Silibank Mail Relays & Rogue Certificate Hierarchy — OTX Detection Pack
OTX pulse exposes North Korea's Hangro state VPN/mail infrastructure spanning Pyongyang, Russian Far East & Chinese netblocks. Rogue certs, mail relays identified. Hunt now.
SectopRAT via Fake Claude Desktop Installers: Bing Malvertising, EtherHiding C2 & DLL Sideloading — OTX Detection Pack
FakeAgent campaign pushes trojanized Claude Desktop installers via Bing malvertising, delivering SectopRAT through DLL sideloading, EtherHiding blockchain C2, and scheduled task persistence.
BOOBA PROJECT Ransomware Group: 6 New Leak-Site Listings Across Government, Healthcare & Education — Sector Analysis & Detection Rules
BOOBA PROJECT listed 6 organizations on its dark web leak site across government, healthcare, and education sectors. All listings are unverified single-source claims — review detection rules now.
AvisLoader Windows Loader: Tox P2P C2 + ClickFix Social Engineering — OTX Detection & Hunting Pack
New AvisLoader malware uses Tox P2P encrypted C2 to survive takedowns. Delivered via ClickFix lures with UAC bypass and shortcut persistence. Hunt now.
ClickFix Fake CAPTCHA Chains, UTA0565 Chrome/Windows 0-Days & Red Heron Kapibala: OTX Pulse Analysis — Enterprise Detection Pack
CRITICAL: Bulletproof-hosted ClickFix malware chains, Chinese APT zero-day phishing (UTA0565), and Red Heron WordPress exploitation hitting governments globally.
ClickFix AS202412 Infostealer Chains + Red Heron WordPress Raids: OTX Detection Pack for DarkGate, Amadey, Matanbuchus
OTX pulses: ClickFix fake-CAPTCHA chains on AS202412 and Red Heron WordPress/gov record theft; credential exposure high-block IOCs, hunt now.
N0N Ransomware Gang: 7 New Leak-Site Listings Across Tech, Retail, Finance & Government — Sourcing, Sectors & Detection Rules
N0N listed 7 organizations on its dark web leak site this week spanning technology, retail, finance, and government sectors. All listings are single-source, unverified criminal claims — detection content inside.
DarkMe RAT, RemControl Banking Trojan & ClickFix Loader Chains: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal credential theft surge: Water Hydra's DarkMe RAT, RemControl Android banking trojan, ClickFix loader chains, and Red Heron WordPress exploitation. Act now.
N0N Ransomware Gang: 13 New Leak-Site Listings in 6 Days — Sector Targeting Analysis & Detection Rules
Dark web leak-site monitoring shows the N0N ransomware gang has listed 13 organizations across 8 countries since Sept 18, spanning tech, finance, retail, healthcare, government, and education. All listings are unverified single-source claims; defenders in affected sectors should review N0N-aligned TTP detection content now.
Equation of Compromise: npm Supply-Chain Loader with Ethereum Smart Contract C2 — OTX Pulse Detection Pack
Sophisticated 6-month npm supply-chain campaign targets DeFi/quant developers via math libraries with encrypted loaders and Ethereum-based C2. Urgent hunt advised.
INC Ransomware Double-Extortion Campaign + DPRK Hangro VPN Infrastructure: OTX Pulse Detection Pack — IAB Handoffs, BYOVD & SoftEther C2
OTX pulses expose INC ransomware's 17-day IAB-to-affiliate attack chain across 175 endpoints and North Korea's Hangro VPN/mail infrastructure on Russian Far East servers. Hunt now.
N0N Ransomware Gang: 13 New Leak-Site Listings — Cross-Sector Targeting Analysis, Verification Caveats & Detection Rules
N0N claims 13 new victims across 8 countries spanning technology, financial services, government, and healthcare. All listings are single-source claims — detection and hardening guidance included.
Vidar Stealer VM-Based String Obfuscation & Custom ChaCha20-Style Ciphers: OTX Pulse Analysis — Enterprise Detection Pack
Vidar infostealer deploys bytecode VM and custom ARX stream ciphers to defeat string analysis. Credential theft at scale — hunt now, rotate exposed identities within 24h.
QILIN Ransomware Gang: 14 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
QILIN listed 14 organizations on its dark web leak site in five days, spanning manufacturing, technology, retail, transportation, agriculture, and energy across 8+ countries. Claims remain unverified — defensive guidance inside.
Typosquatted AI Platform Malware Distribution: 'claude.ai.download-app.us' Credential-Harvesting Campaign — OTX Detection Pack
OTX pulse confirms adversaries abusing trusted AI platform branding (claude.ai typosquats) to distribute credential-harvesting malware across 8 critical sectors. Hunt now.
N0N Ransomware Gang: 12 Victims Posted in 5-Day Surge — Cross-Sector Campaign Analysis, CVE Correlation & Detection Engineering
N0N posted 12 victims in 5 days spanning retail, fintech, government, healthcare and education across 8 countries. Edge-device CVE exploitation suspected; retail, financial services and education orgs must act now.
N0N Ransomware Gang: 11 New Victims in 72 Hours — Financial Services, Government & Telecom Targeting Analysis With Detection Rules
Dark web monitoring confirms N0N posted 11 victims in 72 hours, hitting financial services, telecom, government, and healthcare across 8 countries. Detection rules and IR priorities inside.
METAENCRYPTOR Ransomware Gang: 7 Organizations Listed in 5 Days — Healthcare & Manufacturing Focus With Edge-Device Exploitation
METAENCRYPTOR listed 7 organizations in 5 days — unverified leak-site claims. Detection rules, KQL hunts, and IR priorities inside.
N0N Ransomware Gang: 11 Victims in 4 Days — Cross-Sector Campaign Analysis, KEV Correlation & Detection Engineering
Dark web monitoring of the N0N leak site shows 11 victims posted across 8 countries in 4 days, spanning retail, finance, healthcare, and government. Detection rules and hunt queries inside.
AKIRA Ransomware Gang: 4 New Victims Posted — US/Brazil Targeting, CVE Correlation & Detection Rules
Akira posted 4 new victims across Manufacturing, Professional Services, Tech, and Retail in the US and Brazil. Edge-device CVEs in active exploitation demand immediate patching and hunt operations.
Operation DreamJob Resurfaces: Lazarus LightlessCan, NickelLoader and BLINDINGCAN Trojanized Coding Challenges — OTX Detection Pack
Lazarus Operation DreamJob spearphishing targets aerospace via fake Meta recruiter coding tests; hunt LightlessCan, NickelLoader, BLINDINGCAN IOCs now.
N0N Ransomware Gang: 11 Victims in 4 Days — Cross-Sector Extortion Campaign Targeting FinServ, Education & Critical Telecom
N0N posted 11 victims across 8 countries in a 4-day burst, hitting financial services, education, healthcare and a national ISP. FinServ and EDU defenders should hunt for edge-device exploitation and pre-encryption staging now.
KRYBIT Ransomware Gang: 3 New Victims Posted to Leak Site — Turkey/Germany Targeting, Healthcare Exposure & Detection Rules
KRYBIT posted 3 victims (Technology, Healthcare, TR/DE) to its dark web leak site in 4 days. Edge device CVEs in active ransomware use demand immediate patching and hunting.
N0N Ransomware Gang: 11 Victims in 48 Hours — Cross-Sector Campaign Analysis, Leak-Site Intelligence & Detection Rules
N0N posted 11 victims in 48 hours spanning retail, finance, healthcare, government and education across 8 countries. Enterprise SOC and IR teams in these sectors should activate pre-ransomware hunt playbooks now.
ARCUSMEDIA Ransomware Gang: 3 Victims in 4 Days — BR/CA Tech and Government-Defense Targeting With Edge-CVE Access Signals
ArcusMedia posted 3 victims in 4 days across BR/CA tech and government-defense; edge/VPN CVE exposure and pre-encryption staging demand immediate hunting.
Showing 50 of 1319 reports. Archive expands automatically as new intel is generated.
Every Telegram Intel Report Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.