REVSTEALER Telegram tdata Session Theft for Account Takeover
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
Microsoft Sentinel (KQL)

