HEAVYGRAM 'dt' command exfiltrates Telegram Desktop tdata session

This rule detects unauthorized or suspicious processes (like Python scripts or random executables) accessing Telegram Desktop's local 'tdata' directory, which contains user session information, and simultaneously exhibiting network activity directed towards Telegram API domains. This behavior is highly indicative of infostealer activity, where a malicious process attempts to harvest local Telegram session data for exfiltration.