
TeleShadow2
TeleShadow - Telegram Desktop Session Stealer (Windows)
malware-analysisremote-access-trojan

TeleShadow - Telegram Desktop Session Stealer (Windows)

Steals Telegram Desktop session files by bypassing two-step verification and security mechanisms, exfiltrating via SMTP or Telegram API with proxy…

Fully undetected grabber (grabs wallets, passwords, cookies, modifies discord client etc.)

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…