Dark Side Intelligence Category

Telegram Intel Intelligence

Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.

1033 reports availableRefreshed every 5 minutes

Telegram Intel — Archive & Latest

50 reports loaded
Telegram Intel

GLOBAL SECRET GROUP Ransomware: 3 US Victims in 4 Days — Manufacturing, Retail & Healthcare Targeting Analysis with Detection Rules

Global Secret Group posted 3 US victims in 4 days across manufacturing, retail, and healthcare. Detection rules, KQL hunts, and hardening priorities for exposed perimeter and RMM access vectors.

Aug 17, 2026
Read →
Telegram Intel

Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack

Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.

Aug 17, 2026
Read →
Telegram Intel

Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack

Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.

Aug 17, 2026
Read →
Telegram Intel

BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules

BLACKWATER posted 2 victims (IN, AR) to its dark web leak site on 2026-08-15. Healthcare & professional services orgs should hunt for VPN exploitation and pre-encryption staging now.

Aug 17, 2026
Read →
Telegram Intel

PANZER Ransomware Gang: 3 New Victims Posted — Central European Targeting, Sector Analysis & Detection Rules

PANZER posted 3 victims in 72 hours, hitting manufacturing and technology firms in CZ/DE. European industrials must harden VPN and RDP edges now.

Aug 17, 2026
Read →
Telegram Intel

QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules

QILIN posted 15+ victims in a single day spanning manufacturing, financial services, transportation, and education across 8 countries. Enterprise defenders must patch Check Point, ConnectWise, and Exchange CVEs now.

Aug 17, 2026
Read →
Telegram Intel

LOCKBIT5 Ransomware Gang: 5 New Victims Posted in 48 Hours — European Campaign Analysis, CVE Exploitation Links & Detection Rules

LOCKBIT5 posted 5 victims in 48 hours across Germany, Italy, and France, hitting technology, energy, agriculture, and professional services. Patch Check Point, ScreenConnect, and Exchange now.

Aug 16, 2026
Read →
Telegram Intel

MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Campaign Analysis, Pre-Encryption Hunt Logic & Containment Playbook

MEDUSALOCKER posted 5 victims across tech, retail, manufacturing and transport in GB/DE/FR/ZA. Patch edge CVEs, hunt PsExec/WMI staging, isolate backup paths now.

Aug 16, 2026
Read →
Telegram Intel

XPL0ITRS Ransomware Gang: 3 New Victims Posted — Retail & Tech Sector Targeting Analysis with Detection Engineering

XPL0ITRS posted 3 new victims to its dark web leak site on 2026-08-15, spanning AU retail and US technology. Enterprises running Check Point, ScreenConnect, or Exchange must act now.

Aug 16, 2026
Read →
Telegram Intel

NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack

NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.

Aug 16, 2026
Read →
Telegram Intel

DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection Rules

DIREWOLF posted 6 victims in a single burst across healthcare, tech, and financial services in GB/US/BR/IN. Detection rules and IR priorities for defenders inside.

Aug 16, 2026
Read →
Telegram Intel

HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack

Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.

Aug 15, 2026
Read →
Telegram Intel

PAYLOAD Ransomware Gang: 4 New Victims Posted in 5 Days — DACH/Levant Targeting Analysis & Detection Engineering

PAYLOAD posted 4 new victims across Jordan, Germany, and Switzerland, hitting financial services, manufacturing, professional services, and tech. Mid-market orgs in DACH and the Levant should harden VPN/RDP perimeters now.

Aug 15, 2026
Read →
Telegram Intel

CISA KEV Flash: 3 CVEs Added — Cisco Firewalls, Windows WinSock & Metabase Under Active Attack

CISA confirms active exploitation of Cisco ASA/FTD heap flaw, Windows WinSock use-after-free, and Metabase unauthenticated SQLi. Patch per CISA deadlines now.

Aug 15, 2026
Read →
Telegram Intel

GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack

Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.

Aug 15, 2026
Read →
Telegram Intel

Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack

OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.

Aug 15, 2026
Read →
Telegram Intel

Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack

UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.

Aug 15, 2026
Read →
Telegram Intel

Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack

OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.

Aug 15, 2026
Read →
Telegram Intel

THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection Rules

THEGENTLEMEN posted 15 victims in 24 hours spanning healthcare, manufacturing, retail and technology across 8 countries. Technology, healthcare and SMB-sector orgs must patch exposed gateways and hunt for pre-encryption staging now.

Aug 15, 2026
Read →
Telegram Intel

Project CAV3RN Espionage Framework: Google Apps Script C2 + DNS Channel Rotation Targeting Israel — OTX Detection Pack

Modular espionage framework CAV3RN targets Israeli entities using DNS A-record logic to rotate between HTTPS and Google Apps Script C2. High urgency for Israel-facing orgs.

Aug 14, 2026
Read →
Telegram Intel

BandCamPro 'Patriot Bait' Campaign: AI-Deployed C2 Botnet via Google Gemini CLI — OTX Pulse Analysis & Healthcare Detection Pack

Russian-speaking actor 'bandcampro' used Google Gemini CLI to build and migrate a C2 botnet in six minutes, compromising dental clinic systems across the US and Canada. High urgency.

Aug 14, 2026
Read →
Telegram Intel

Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack

~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.

Aug 14, 2026
Read →
Telegram Intel

COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture & Manufacturing Targeting Analysis with Detection Rules

COINBASECARTEL posted 4 victims across GB, US, and JP in 48 hours, hitting professional services, agriculture, and manufacturing. Edge VPN and remote access exploitation likely vectors — patch and hunt now.

Aug 14, 2026
Read →
Telegram Intel

SocGholish Dropcatch Scavengers + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal dropcatched domains feeding SocGholish/Keitaro fraud and CAV3RN espionage framework using Google Apps Script C2 against Israel. High urgency.

Aug 14, 2026
Read →
Telegram Intel

Mustang Panda CoolClient Kernel Rootkit, TA416 EU Espionage & AI-Built 'Patriot Bait' Botnet: OTX Pulse Analysis — Enterprise Detection Pack

HoneyMyte/Mustang Panda deploys CoolClient with a signed kernel rootkit; TA416 resumes EU espionage; an AI-assisted botnet hit US/CA healthcare. High urgency.

Aug 14, 2026
Read →
Telegram Intel

Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack

OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.

Aug 14, 2026
Read →
Telegram Intel

PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack

OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.

Aug 14, 2026
Read →
Telegram Intel

SILENTRANSOMGROUP: 5 Victims Posted in 72 Hours — Legal & Professional Services Targeting Analysis with Detection Rules

SILENTRANSOMGROUP posted 5 victims in 72 hours, concentrated on law firms and professional services in the US and Germany. Legal and professional services orgs must act now.

Aug 14, 2026
Read →
Telegram Intel

Multi-Stage Phishing Redirection Chains: Framer & Cloudflare Workers Abuse with HTML Smuggling — OTX Pulse Detection Pack

OTX pulse exposes multi-stage phishing chains abusing Framer, Cloudflare Workers, and Blob API HTML smuggling to deliver credential theft pages. Enterprise detection pack included.

Aug 13, 2026
Read →
Telegram Intel

Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack

OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.

Aug 13, 2026
Read →
Telegram Intel

KRYBIT Ransomware: 5 Victims Posted in 48 Hours — Cross-Regional Campaign Hits Healthcare & Professional Services, Detection Rules Inside

KRYBIT posted 5 victims across TW, IN, SG, FI, and AR in 48 hours, including a healthcare org. Edge-device and RMM exploitation are the likely access vectors — hunt and patch now.

Aug 13, 2026
Read →
Telegram Intel

TencShell/Vshell AI-Assisted Intrusions + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack

Two active campaigns exposed: AI-assisted intrusions hitting government networks across 4 nations, and CAV3RN espionage framework abusing Google Apps Script for stealth C2 in Israel. URGENT.

Aug 13, 2026
Read →
Telegram Intel

LabubaRAT Rust Implant + Multi-Stage Phishing Relay Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose LabubaRAT (Rust RAT spoofing NVIDIA software) and multi-stage phishing chains abusing Cloudflare Workers & Framer. Urgent hunt guidance inside.

Aug 13, 2026
Read →
Telegram Intel

Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack

Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.

Aug 13, 2026
Read →
Telegram Intel

INCRANSOM Ransomware Gang: 5 Victims Posted in 24 Hours — Energy, Healthcare & Professional Services Targeting Analysis with Detection Rules

INCRANSOM posted 5 victims on Aug 12 spanning Technology, Energy, Healthcare and Professional Services across US/AU. Detection rules and IR priorities inside.

Aug 13, 2026
Read →
Telegram Intel

ShinyHunters OAuth Abuse + DarkHotel North Korea Lures + Jewelbug Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

OTX intel on ShinyHunters Salesforce OAuth vishing, DarkHotel MSI/shellcode phishing, and Jewelbug's Antino espionage backdoor. Defense, gov, SaaS targets. High urgency.

Aug 13, 2026
Read →
Telegram Intel

Cl0p LEMURLOOT MFT Zero-Days, Armored Likho Still Toolkit Rust Espionage + Multi-Stage Phishing Relay: OTX Pulse Detection Pack

OTX: Cl0p MFT zero-days, Armored Likho Still Toolkit Rust espionage, multi-stage phishing; hunt C2, Rust droppers, Cloudflare/Framer redirection.

Aug 13, 2026
Read →
Telegram Intel

Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.

Aug 13, 2026
Read →
Telegram Intel

BLACKNEVAS Ransomware: MSP Supply-Chain Intrusion Yields 5 Victims in 48 Hours — Sector Analysis & Detection Engineering

BLACKNEVAS posted 5 victims in 48 hours, all downstream clients of compromised MSP 'Computer Country and Networks.' Technology, healthcare, and agri-food orgs in US/CA must act now.

Aug 13, 2026
Read →
Telegram Intel

O&O Syspectr RAT Masquerading as CNN, Avast & Stremio Apps: Lookalike-Domain Social Engineering Campaign — OTX Pulse Analysis

Fake CNN, Avast, and Stremio sites push attacker-linked O&O Syspectr RMM installers. Windows users targeted. Block lookalike domains; hunt Syspectr installs now.

Aug 12, 2026
Read →
Telegram Intel

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack

APT29 hijacks hotel captive portals for M365 credential theft while ShinyHunters and UNC6671 escalate OAuth abuse and vishing extortion against SaaS. Block IOCs now.

Aug 12, 2026
Read →
Telegram Intel

CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack

OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.

Aug 12, 2026
Read →
Telegram Intel

MAJINAHANASHI Ransomware Gang: 5 Victims in 48 Hours — Cross-Sector Leak Activity, Likely Edge-CVE Access Paths & Detection Rules

MAJINAHANASHI posted 5 victims in ~48h across tech, healthcare and energy in US/LT/CL/CH; edge-VPN, RMM and Exchange/FMC CVE exploitation should be hunted now.

Aug 12, 2026
Read →
Telegram Intel

Aeternum Blockchain C2, Midnight Blizzard 'CaptiveCrunch' M365 Credential Theft, and GoldDigger Android Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal Polygon blockchain C2 botnets, APT29 hotel captive-portal M365 credential theft, and GoldDigger Android banking trojan targeting finance. High urgency — detect now.

Aug 12, 2026
Read →
Telegram Intel

Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack

OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.

Aug 12, 2026
Read →
Telegram Intel

CLOP Ransomware Gang: 44 Victims Posted in Latest Leak Site Dump — Exploit-Driven Campaign Analysis & Detection Rules

CLOP posted 44 victims in its latest leak site wave, spanning tech, manufacturing, government & defense, and transportation across 8+ countries. Patch edge CVEs and hunt staging TTPs now.

Aug 12, 2026
Read →
Telegram Intel

CNCMachineRMS RAT, Lazarus Operation Dream Job Zero-Day & APT-C-60 SpyGlace: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose a ClickFix-delivered CNCMachineRMS RAT, Lazarus zero-day job-lure attacks on defense/aerospace, and APT-C-60 SpyGlace campaigns hitting Japan. High urgency.

Aug 12, 2026
Read →
Telegram Intel

Evilginx AiTM, Midnight Blizzard CaptiveCrunch, APT37 RokRAT: OTX Detection Pack

OTX pulses expose AiTM phishing crews, APT29 hotel captive-portal M365 theft, and APT37 RokRAT spear-phishing; prioritize credential reset, DNS blocking, hunts.

Aug 12, 2026
Read →
Telegram Intel

Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack

Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.

Aug 12, 2026
Read →
Telegram Intel

GENESIS Ransomware Gang: 4 Victims Posted in 48 Hours — US Healthcare Under Active Targeting, Detection Rules Inside

GENESIS posted 4 victims to its dark web leak site in 48 hours, with 3 of 4 hitting US healthcare providers. Healthcare and mid-market US orgs should review edge device exposure and pre-encryption staging indicators now.

Aug 12, 2026
Read →

Showing 50 of 1033 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Telegram IntelReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.