Product
high
advisory
Windows DNS Query to Telegram Bot API Indicating Malware C2
1 rule 2 TTPs 1 IOCThis brief details the detection of suspicious DNS queries from non-Telegram processes to api.telegram.org on Windows systems, a strong indicator of malware utilizing the Telegram Bot API for command and control (C2) communications to receive commands or exfiltrate data.
Telegram Bot API
network
command-and-control
c2
telegram
windows
malware
1r
2t
1i
high
advisory
Suspicious DNS Queries to Telegram Bot API
2 rules 2 TTPs 1 IOCDetection of DNS queries to api.telegram.org by processes other than telegram.exe indicates potential command and control communication via Telegram bots, a technique leveraged by malware to establish covert communication channels.
Telegram Bot API
telegram
bot
c2
command-and-control
dns
2r
2t
1i