HEAVYGRAM Backdoor Exfiltrates Telegram Desktop tdata via '##dt' Command

Detects instances where processes other than the legitimate Telegram Desktop application or its updater attempt to access files within the Telegram Desktop 'tdata' directory. This directory contains session information, which can be harvested by malicious actors to hijack user sessions or access sensitive information.