๐๐ฑ๐ฉ๐๐ง๐๐ข๐ง๐ ๐๐ข๐ฌ๐ข๐๐ข๐ฅ๐ข๐ญ๐ฒ ๐๐ก๐ซ๐จ๐ฎ๐ ๐ก ๐๐๐ฅ๐๐ ๐ซ๐๐ฆ ๐๐จ๐ญ ๐๐ง๐ญ๐๐ซ๐๐๐ฉ๐ญ๐ข๐จ๐ง
Using Telegramโs API, the team was able to intercept and analyze live data exfiltration flows, giving them rare visibility into the attackerโs operations. This pivot turned a single sandbox session into a broader investigation, revealing credential theft across multiple regions, repeated bot infrastructure reuse, and signs that the campaign is driven by access brokers rather than highly advanced threat actors.
๐๐๐ฒ ๐๐๐ค๐๐๐ฐ๐๐ฒ๐ฌ ๐๐ซ๐จ๐ฆ ๐ญ๐ก๐ ๐๐๐ฌ๐ ๐๐ญ๐ฎ๐๐ฒ
Key insights from this in-depth case study include:
ยท Telegram bots were used as exfiltration channels, with hardcoded tokens and chat IDs embedded in phishing scripts
ยท Campaign impersonates Microsoft OneNote, Outlook, and Italyโs PEC system
ยท Hosted on low-cost/free infrastructure: Notion, Glitch, RenderForest, and others
ยท One of the attacks targeted Italian companies, including A&D, Steelsystem Building, Gruppo Amag, and others.
ยท Threat activity traced from 2022 to 2025, still active at the time of publication
ยท Victims span industries like logistics, utilities, finance, and digital identity
ยท ANY.RUN shares detection assets: IOCs, YARA rules, Suricata rules, and Telegram analysis scripts
ยท Attribution remains uncertain, but patterns suggest credential resale and access brokering
To explore the full technical analysis, including Telegram bot scripts, victim profiling, and detection recommendations, visit ANY.RUNโs blog.
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN is a cybersecurity provider offering a suite of advanced tools for malware analysis and threat intelligence. Its interactive sandbox supports real-time analysis across Windows, Linux, and Android environments, giving security professionals hands-on visibility into malicious behavior. Trusted by over 15,000 companies worldwide, ANY.RUN also offers comprehensive Threat Intelligence solutions, including TI Lookup, Feeds, and YARA Search, to help teams detect threats faster and respond with confidence.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
Twitter