Chinese APT Telegram Bot API C2 via Non-Messaging Process (T1102.002)

Detects network connections to the Telegram API (api.telegram.org) from processes identified as LOLBins or residing in suspicious, potentially writable locations such as Temp, AppData, or user-defined directories. This activity is often indicative of C2 communication or data exfiltration by malware bypassing standard messaging client restrictions.