MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake “election seminar” Word files.
It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection.
It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection.
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure.
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading.
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware.
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks.
Cyber Dispatch™️
Goodbye, dark Telegram: Blocks are pushing the underground out.
Telegram has won over users worldwide. While the average user chooses a messaging app based on convenience, user experience and stability (and perhaps, cool stickers).
When it comes to anonymity, privacy and application independence – essential criteria for a shadow messaging app – Telegram is not as strong as its direct competitors.
It lacks default end-to-end (E2E) encryption for chats.
It has a centralized infrastructure: users cannot set up their own servers for communication.
Its server-side code is closed: users cannot verify what it does.
This architecture requires a high degree of trust in the platform, but experienced cybercriminals prefer not to rely on third parties when it comes to protecting their operations and, more importantly, their personal safety.
That said, Telegram today is widely viewed and used not only as a communication tool (messaging service), but also as a full-fledged dark-market business platform – thanks to several features that underground communities actively exploit.
Is this research, we examine Telegram through the eyes of cybercriminals, evaluate its technical capabilities for running underground operations, and analyze the lifecycle of a Telegram channel from creation to digital death. For this purpose, we analyzed more than 800 blocked Telegram channels, which existed between 2021 and 2024.
Key findings
The median lifespan of a shadow Telegram channel increased from five months in 2021–2022 to nine months in 2023–2024.
The frequency of blocking cybercrime channels has been growing since October 2024.
Cybercriminals have been migrating to other messaging services due to frequent blocks by Telegram.
When it comes to anonymity, privacy and application independence – essential criteria for a shadow messaging app – Telegram is not as strong as its direct competitors.
It lacks default end-to-end (E2E) encryption for chats.
It has a centralized infrastructure: users cannot set up their own servers for communication.
Its server-side code is closed: users cannot verify what it does.
This architecture requires a high degree of trust in the platform, but experienced cybercriminals prefer not to rely on third parties when it comes to protecting their operations and, more importantly, their personal safety.
That said, Telegram today is widely viewed and used not only as a communication tool (messaging service), but also as a full-fledged dark-market business platform – thanks to several features that underground communities actively exploit.
Is this research, we examine Telegram through the eyes of cybercriminals, evaluate its technical capabilities for running underground operations, and analyze the lifecycle of a Telegram channel from creation to digital death. For this purpose, we analyzed more than 800 blocked Telegram channels, which existed between 2021 and 2024.
Key findings
The median lifespan of a shadow Telegram channel increased from five months in 2021–2022 to nine months in 2023–2024.
The frequency of blocking cybercrime channels has been growing since October 2024.
Cybercriminals have been migrating to other messaging services due to frequent blocks by Telegram.
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data.
Microsoft just fixed 56 Windows bugs — one’s already being exploited.
It hides in the Cloud Files driver used by OneDrive, Google Drive, and iCloud — even if those apps aren’t installed. Hackers can chain it with phishing to gain SYSTEM access.
Plus: 2 zero-days in PowerShell and GitHub Copilot for JetBrains.
It hides in the Cloud Files driver used by OneDrive, Google Drive, and iCloud — even if those apps aren’t installed. Hackers can chain it with phishing to gain SYSTEM access.
Plus: 2 zero-days in PowerShell and GitHub Copilot for JetBrains.