Telegram Intel Intelligence
Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.
Telegram Intel — Archive & Latest
GLOBAL SECRET GROUP Ransomware: 3 US Victims in 4 Days — Manufacturing, Retail & Healthcare Targeting Analysis with Detection Rules
Global Secret Group posted 3 US victims in 4 days across manufacturing, retail, and healthcare. Detection rules, KQL hunts, and hardening priorities for exposed perimeter and RMM access vectors.
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack
Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.
Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack
Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.
BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules
BLACKWATER posted 2 victims (IN, AR) to its dark web leak site on 2026-08-15. Healthcare & professional services orgs should hunt for VPN exploitation and pre-encryption staging now.
PANZER Ransomware Gang: 3 New Victims Posted — Central European Targeting, Sector Analysis & Detection Rules
PANZER posted 3 victims in 72 hours, hitting manufacturing and technology firms in CZ/DE. European industrials must harden VPN and RDP edges now.
QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules
QILIN posted 15+ victims in a single day spanning manufacturing, financial services, transportation, and education across 8 countries. Enterprise defenders must patch Check Point, ConnectWise, and Exchange CVEs now.
LOCKBIT5 Ransomware Gang: 5 New Victims Posted in 48 Hours — European Campaign Analysis, CVE Exploitation Links & Detection Rules
LOCKBIT5 posted 5 victims in 48 hours across Germany, Italy, and France, hitting technology, energy, agriculture, and professional services. Patch Check Point, ScreenConnect, and Exchange now.
MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Campaign Analysis, Pre-Encryption Hunt Logic & Containment Playbook
MEDUSALOCKER posted 5 victims across tech, retail, manufacturing and transport in GB/DE/FR/ZA. Patch edge CVEs, hunt PsExec/WMI staging, isolate backup paths now.
XPL0ITRS Ransomware Gang: 3 New Victims Posted — Retail & Tech Sector Targeting Analysis with Detection Engineering
XPL0ITRS posted 3 new victims to its dark web leak site on 2026-08-15, spanning AU retail and US technology. Enterprises running Check Point, ScreenConnect, or Exchange must act now.
NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack
NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.
DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection Rules
DIREWOLF posted 6 victims in a single burst across healthcare, tech, and financial services in GB/US/BR/IN. Detection rules and IR priorities for defenders inside.
HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack
Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.
PAYLOAD Ransomware Gang: 4 New Victims Posted in 5 Days — DACH/Levant Targeting Analysis & Detection Engineering
PAYLOAD posted 4 new victims across Jordan, Germany, and Switzerland, hitting financial services, manufacturing, professional services, and tech. Mid-market orgs in DACH and the Levant should harden VPN/RDP perimeters now.
CISA KEV Flash: 3 CVEs Added — Cisco Firewalls, Windows WinSock & Metabase Under Active Attack
CISA confirms active exploitation of Cisco ASA/FTD heap flaw, Windows WinSock use-after-free, and Metabase unauthenticated SQLi. Patch per CISA deadlines now.
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack
Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.
Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack
OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.
Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack
UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.
Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack
OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.
THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection Rules
THEGENTLEMEN posted 15 victims in 24 hours spanning healthcare, manufacturing, retail and technology across 8 countries. Technology, healthcare and SMB-sector orgs must patch exposed gateways and hunt for pre-encryption staging now.
Project CAV3RN Espionage Framework: Google Apps Script C2 + DNS Channel Rotation Targeting Israel — OTX Detection Pack
Modular espionage framework CAV3RN targets Israeli entities using DNS A-record logic to rotate between HTTPS and Google Apps Script C2. High urgency for Israel-facing orgs.
BandCamPro 'Patriot Bait' Campaign: AI-Deployed C2 Botnet via Google Gemini CLI — OTX Pulse Analysis & Healthcare Detection Pack
Russian-speaking actor 'bandcampro' used Google Gemini CLI to build and migrate a C2 botnet in six minutes, compromising dental clinic systems across the US and Canada. High urgency.
Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack
~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.
COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture & Manufacturing Targeting Analysis with Detection Rules
COINBASECARTEL posted 4 victims across GB, US, and JP in 48 hours, hitting professional services, agriculture, and manufacturing. Edge VPN and remote access exploitation likely vectors — patch and hunt now.
SocGholish Dropcatch Scavengers + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal dropcatched domains feeding SocGholish/Keitaro fraud and CAV3RN espionage framework using Google Apps Script C2 against Israel. High urgency.
Mustang Panda CoolClient Kernel Rootkit, TA416 EU Espionage & AI-Built 'Patriot Bait' Botnet: OTX Pulse Analysis — Enterprise Detection Pack
HoneyMyte/Mustang Panda deploys CoolClient with a signed kernel rootkit; TA416 resumes EU espionage; an AI-assisted botnet hit US/CA healthcare. High urgency.
Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack
OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.
PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack
OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.
SILENTRANSOMGROUP: 5 Victims Posted in 72 Hours — Legal & Professional Services Targeting Analysis with Detection Rules
SILENTRANSOMGROUP posted 5 victims in 72 hours, concentrated on law firms and professional services in the US and Germany. Legal and professional services orgs must act now.
Multi-Stage Phishing Redirection Chains: Framer & Cloudflare Workers Abuse with HTML Smuggling — OTX Pulse Detection Pack
OTX pulse exposes multi-stage phishing chains abusing Framer, Cloudflare Workers, and Blob API HTML smuggling to deliver credential theft pages. Enterprise detection pack included.
Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack
OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.
KRYBIT Ransomware: 5 Victims Posted in 48 Hours — Cross-Regional Campaign Hits Healthcare & Professional Services, Detection Rules Inside
KRYBIT posted 5 victims across TW, IN, SG, FI, and AR in 48 hours, including a healthcare org. Edge-device and RMM exploitation are the likely access vectors — hunt and patch now.
TencShell/Vshell AI-Assisted Intrusions + Project CAV3RN Google Apps Script C2: OTX Pulse Analysis — Enterprise Detection Pack
Two active campaigns exposed: AI-assisted intrusions hitting government networks across 4 nations, and CAV3RN espionage framework abusing Google Apps Script for stealth C2 in Israel. URGENT.
LabubaRAT Rust Implant + Multi-Stage Phishing Relay Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose LabubaRAT (Rust RAT spoofing NVIDIA software) and multi-stage phishing chains abusing Cloudflare Workers & Framer. Urgent hunt guidance inside.
Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack
Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.
INCRANSOM Ransomware Gang: 5 Victims Posted in 24 Hours — Energy, Healthcare & Professional Services Targeting Analysis with Detection Rules
INCRANSOM posted 5 victims on Aug 12 spanning Technology, Energy, Healthcare and Professional Services across US/AU. Detection rules and IR priorities inside.
ShinyHunters OAuth Abuse + DarkHotel North Korea Lures + Jewelbug Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
OTX intel on ShinyHunters Salesforce OAuth vishing, DarkHotel MSI/shellcode phishing, and Jewelbug's Antino espionage backdoor. Defense, gov, SaaS targets. High urgency.
Cl0p LEMURLOOT MFT Zero-Days, Armored Likho Still Toolkit Rust Espionage + Multi-Stage Phishing Relay: OTX Pulse Detection Pack
OTX: Cl0p MFT zero-days, Armored Likho Still Toolkit Rust espionage, multi-stage phishing; hunt C2, Rust droppers, Cloudflare/Framer redirection.
Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.
BLACKNEVAS Ransomware: MSP Supply-Chain Intrusion Yields 5 Victims in 48 Hours — Sector Analysis & Detection Engineering
BLACKNEVAS posted 5 victims in 48 hours, all downstream clients of compromised MSP 'Computer Country and Networks.' Technology, healthcare, and agri-food orgs in US/CA must act now.
O&O Syspectr RAT Masquerading as CNN, Avast & Stremio Apps: Lookalike-Domain Social Engineering Campaign — OTX Pulse Analysis
Fake CNN, Avast, and Stremio sites push attacker-linked O&O Syspectr RMM installers. Windows users targeted. Block lookalike domains; hunt Syspectr installs now.
Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack
APT29 hijacks hotel captive portals for M365 credential theft while ShinyHunters and UNC6671 escalate OAuth abuse and vishing extortion against SaaS. Block IOCs now.
CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack
OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.
MAJINAHANASHI Ransomware Gang: 5 Victims in 48 Hours — Cross-Sector Leak Activity, Likely Edge-CVE Access Paths & Detection Rules
MAJINAHANASHI posted 5 victims in ~48h across tech, healthcare and energy in US/LT/CL/CH; edge-VPN, RMM and Exchange/FMC CVE exploitation should be hunted now.
Aeternum Blockchain C2, Midnight Blizzard 'CaptiveCrunch' M365 Credential Theft, and GoldDigger Android Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal Polygon blockchain C2 botnets, APT29 hotel captive-portal M365 credential theft, and GoldDigger Android banking trojan targeting finance. High urgency — detect now.
Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack
OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.
CLOP Ransomware Gang: 44 Victims Posted in Latest Leak Site Dump — Exploit-Driven Campaign Analysis & Detection Rules
CLOP posted 44 victims in its latest leak site wave, spanning tech, manufacturing, government & defense, and transportation across 8+ countries. Patch edge CVEs and hunt staging TTPs now.
CNCMachineRMS RAT, Lazarus Operation Dream Job Zero-Day & APT-C-60 SpyGlace: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose a ClickFix-delivered CNCMachineRMS RAT, Lazarus zero-day job-lure attacks on defense/aerospace, and APT-C-60 SpyGlace campaigns hitting Japan. High urgency.
Evilginx AiTM, Midnight Blizzard CaptiveCrunch, APT37 RokRAT: OTX Detection Pack
OTX pulses expose AiTM phishing crews, APT29 hotel captive-portal M365 theft, and APT37 RokRAT spear-phishing; prioritize credential reset, DNS blocking, hunts.
Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack
Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.
GENESIS Ransomware Gang: 4 Victims Posted in 48 Hours — US Healthcare Under Active Targeting, Detection Rules Inside
GENESIS posted 4 victims to its dark web leak site in 48 hours, with 3 of 4 hitting US healthcare providers. Healthcare and mid-market US orgs should review edge device exposure and pre-encryption staging indicators now.
Showing 50 of 1033 reports. Archive expands automatically as new intel is generated.
Every Telegram IntelReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.