Telegram Intel Intelligence
Live threat intelligence collected from criminal Telegram channels — real-time threat actor communications, malware distribution campaigns, and first-look intelligence before it hits mainstream reporting.
Telegram Intel — Archive & Latest
KRYBIT Ransomware Gang: 5 New Victims Posted — Healthcare and Education Targeting With Perimeter-Edge CVE Pressure
KRYBIT posted 5 new victims across healthcare, professional services, education and agri-food; defenders should prioritize edge-VPN, ScreenConnect, Exchange and pre-encryption staging hunts.
PANZER Ransomware: 4 Victims Posted in 72 Hours — European & Middle East Targeting, Sector Analysis & Detection Rules
PANZER posted 4 victims in 72 hours across Saudi Arabia, Germany, and Indonesia, hitting government, education, and professional services. Detection rules and IR priorities inside.
Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack
Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.
UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack
UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.
THEGENTLEMEN Ransomware Gang: 5 Victims in 5 Days — Transportation, Healthcare & Technology Under Active Fire
THEGENTLEMEN posted 5 victims across 4 countries in 5 days, hitting Transportation, Healthcare, Retail, and Tech. Enterprises with exposed VPNs, RDP, or unpatched KEV flaws should hunt now.
MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack
MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.
MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack
MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.
DIREWOLF Ransomware: 6 Victims in 5 Days — Cross-Sector Campaign Hits US Tech, Thai Energy, and Global Manufacturing
DIREWOLF posted 6 victims in 5 days spanning tech, energy, transportation, and manufacturing across US, ZA, TH, BR, ID. Edge-VPN and remote access exploitation suspected. Patch and hunt now.
SPACEBEARS Ransomware Gang: 3 Fresh Leak-Site Victims — US/IT Sector Pressure, KEV Edge Exposure & Pre-Encryption Hunt Rules
SPACEBEARS posted 3 US/IT victims across retail, professional services and healthcare; patch KEV edge/RMM flaws and hunt pre-encryption staging now.
FDMTP Implant via QuickFox Supply Chain Attack + ENDLESSDOORS Router Backdoor (CVE-2026-66747): OTX Detection Pack
Two supply chain campaigns exposed: trojanized QuickFox VPN installers deploying the FDMTP implant, and Zbtlink routers shipping with the pre-installed ENDLESSDOORS backdoor (CVE-2026-66747).
VEXY Ransomware Gang: 5 New Victims in 4 Days — India & LATAM Campaign, Sector Analysis & Detection Rules
VEXY Ransomware posted 5 victims in 4 days spanning manufacturing, retail, and hospitality across India, Ecuador, and Brazil. Edge-VPN CVEs flagged as likely entry vectors.
TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack
TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.
QILIN Ransomware Gang: 7 Victims in 5 Days — Government, Energy & Manufacturing Targeting with Detection Rules
Qilin (Agenda) posted 7 victims in 5 days across CA, US, CL, TR, AR — hitting government, energy co-ops, and manufacturing. KEV-linked edge exploitation suspected; detection rules included.
SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack
Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.
STORM Ransomware Gang: 8 New Victims in 72 Hours — Energy, Financial & Healthcare Targeting Analysis with Detection Rules
STORM posted 8 victims across CA, US, and AU in 72 hours, hitting energy, financial services, transportation, agriculture, and healthcare. Detection rules and IR priorities inside.
Microsoft Teams Help-Desk Vishing + RMM Lateral Movement: OTX Pulse Detection Pack
OTX flags Teams help-desk impersonation leading to malware execution and lateral movement; 8 IPv4 C2/RMM indicators. Enterprise SOC urgency: high.
The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack
The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.
The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack
OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.
INCRANSOM Ransomware Gang: 11 New Victims in 5 Days — Manufacturing & Healthcare Surge, Detection Rules Inside
INCRANSOM posted 11 victims across 8 countries since Aug 31, hitting manufacturing, healthcare, education and financial services. Detection rules and hunt queries included.
ScreenConnect RMM Abuse + SockTz AI-Enabled Intrusions + Teams Help Desk Vishing: OTX Pulse Analysis — Enterprise Detection Pack
Multi-wave campaigns abuse ScreenConnect RMM, Cloudflare tunnels, AI tooling, and Teams vishing against LATAM and enterprise orgs. Detection pack included. Hunt immediately.
Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack
Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.
Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack
Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.
SILENTRANSOMGROUP Ransomware Campaign: 4 Victims Posted in 48 Hours — BigLaw Targeting Analysis, Detection Rules & Hunting Queries
SILENTRANSOMGROUP posted 4 victims in 48 hours, including major US law firms Greenberg Traurig and Holland & Knight. Professional services orgs must act now.
D2IP C2 Evasion + Rogue ScreenConnect Worm Activity + Teams Help Desk Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal 45% of malware bypassing DNS via direct-to-IP C2, worm-like rogue ScreenConnect RMM deployments dropping XMRig, and Teams help desk vishing. High urgency for education, government, and transportation sectors.
Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack
Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.
Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack
Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.
AKIRA Ransomware Gang: 9 New Victims in 72 Hours — Sector Targeting Analysis, CVE Correlation & Detection Rules
AKIRA posted 9 victims in 72 hours spanning manufacturing, financial services, retail and transportation across the US, NL and DE. Detection rules and IR priorities inside.
Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack
CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack
OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.
LOCKBIT5 Ransomware Gang: 6 Victims Posted in 24 Hours — Financial Services & Manufacturing Targeting Analysis with Detection Rules
LOCKBIT5 posted 6 victims across US, JP, and NL on 2026-08-31, hitting financial services, legal, and manufacturing firms. Detection rules and IR priorities inside.
Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack
OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.
Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack
OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.
XCSSET v40 Supply Chain Surge + SakDriver Kernel Rootkit + Teams Help Desk Intrusion: OTX Detection Pack
OTX pulses reveal XCSSET v40 infecting Xcode dev environments, the SakDriver Ring-0 rootkit evading ETW, and Teams-based help desk intrusion with live C2. High urgency — hunt now.
Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack
OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.
CISA KEV Flash: 11 CVEs Added — PaperCut, Citrix NetScaler & Linux Kernel Under Active Exploitation
CISA confirms active exploitation of 11 CVEs incl. PaperCut NG/MF, Citrix NetScaler, Linux Kernel, JFrog Artifactory & ownCloud. Patch now — federal deadlines apply.
Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack
Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.
Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis
13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.
KRYBIT Ransomware Gang: 14 Victims Posted in Single-Day Surge — Cross-Sector Campaign Analysis & Detection Engineering
KRYBIT posted 14 victims in 24 hours spanning healthcare, education, tech, and transport across 9 countries. Detection rules, KQL hunts, and IR priorities inside.
BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack
OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.
OROVA Ransomware Gang: 4 New Victims Posted — APAC Technology, Manufacturing & Hospitality Targeting Analysis & Detection Rules
OROVA posted 4 new victims to its leak site this week, concentrated in Taiwan and Hong Kong across Technology, Manufacturing, and Hospitality. VPN-edge exploitation and double extortion remain the gang's primary playbook.
EtherHiding Magecart Campaign: Blockchain-Staged Card Skimmers Targeting WooCommerce & Magento — OTX Detection Pack
OTX pulse reveals Magecart operators staging payment skimmers inside Ethereum smart contracts, compromising WooCommerce, PrestaShop and Magento storefronts. High urgency for retail/e-commerce defenders.
BRAINCIPHER Ransomware Gang: 4 New Victims in 24 Hours — Cross-Sector Campaign Analysis & Detection Rules
BRAINCIPHER posted 4 victims across AE, DE, and US on 2026-08-31, spanning healthcare, technology, and professional services. Edge-VPN patching and pre-encryption staging hunts are urgent.
Spring Ring Teams Vishing + EtherHiding Magecart + Gryxa AI-Built Toolkit: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal Teams-based vishing (Spring Ring), blockchain-staged Magecart skimmers, and the AI-built Gryxa RMM toolkit. Retail & enterprise targets. High urgency.
ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack
Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.
JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack
OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.
WALLSTREET Ransomware: US Healthcare and Education Victims Posted — Leak-Site Signals, CVE Access Paths & Detection Rules
WALLSTREET posted Cedar County Memorial Hospital and Andover; US healthcare and education teams should harden VPN, Exchange, RMM and link-following paths now.
Fake MP4 ISO-BMFF Trojan + NetSupport RAT: PowerShell Loader Campaign via Cloudflare Infrastructure — OTX Detection Pack
Active campaign hides encrypted NetSupport Manager RAT inside fake MP4 uuid boxes, delivered via Cloudflare-fronted PowerShell loaders. High urgency — deploy IOCs & hunts now.
Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.
Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack
OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.
CHAOS Ransomware Gang: 3 Victims Posted in 48 Hours — US/GB/AU Targeting, KEV-Linked Access Paths & Detection Rules
CHAOS posted corematerials.com, macallister.com and singleton.com within 48h. Manufacturing and unclassified GB/AU firms should harden VPN/RDP/RMM paths now.
Showing 50 of 1171 reports. Archive expands automatically as new intel is generated.
Every Telegram IntelReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.