Telegram Bot API used as C2 beacon channel with coded action messages
This rule detects network traffic directed at the Telegram Bot API (api.telegram.org) where the request URI indicates a bot action ('/bot' followed by 'sendMessage') and the HTTP request body contains the keyword 'VIEW'. This pattern is commonly associated with C2 beacons using Telegram as an intermediary service to send status or command results from compromised hosts.
Suricata

