• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Telegram Bot API used as C2 beacon channel with coded action messages

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•1

    This rule detects network traffic directed at the Telegram Bot API (api.telegram.org) where the request URI indicates a bot action ('/bot' followed by 'sendMessage') and the HTTP request body contains the keyword 'VIEW'. This pattern is commonly associated with C2 beacons using Telegram as an intermediary service to send status or command results from compromised hosts.

    Suricata

    Tags

    T1071.001 - Web ProtocolsT1102 - Web ServiceNetwork Connection OutboundIDS IPS AlertHTTP RequestNetwork GenericSuricata IDSSnort IDSHTTPCommand And Control

    Found in

    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?