2026 Critical Enterprise Intrusion Chain Detection: Messaging App Session Token Theft via Non-Owner tdata Access
Detects unauthorized processes attempting to read sensitive session files or databases associated with messaging applications like Telegram, Signal, and Discord. Accessing these files (such as 'tdata', 'db.sqlite', or 'leveldb') allows for full account takeover by extracting session tokens, enabling attackers to bypass authentication and 2FA.
SentinelOne

