News

The packages contained an __init__.py file that harboured malicious code, designed to search for files with the .py, .php,.zip, .png, .jpg and .jpeg extensions in the root and DCIM folders, and ...
Threat actors modified the legitimate plugin behavior of sending messages to Telegram using the Telegram Bot API by replacing the Telegram API endpoint (https:/api.telegra.org) with their own (C2 ...
Stealthy C2 messages operated by the Golang backdoor could easily be mistaken for legitimate Telegram API communication.