Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • Encoder & Hash Generator
    • IP / Subnet Calculator
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Russian Telegrab Malware Gather Telegram Credentials, Cookies, Desktop Cache, and Critical Files
  • Malware

Russian Telegrab Malware Gather Telegram Credentials, Cookies, Desktop Cache, and Critical Files

Do Son May 18, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

Security experts at the Cisco Talos Group have discovered a new type of malicious software, Telegrab, that attacks desktop-based end-to-end encrypted instant messaging service Telegram.

The analysis shows that the malware was developed by a Russian-speaking attacker and the target victim is a Russian-speaking user. The malicious code captured by the researchers was a variant of the Telegrab malware and was first used on-site on April 4, 2018, to collect cache and key files from the Telegram application. The second version appeared on April 10, 2018. Unlike the first edition, this edition can also obtain the desktop version of Telegram’s cache and mobile login credentials in addition to the text file, browser credentials, and cookies. Telegram session.

“Over the past month and a half, Talos has seen the emergence of a malware that collects cache and key files from end-to-end encrypted instant messaging service Telegram. This malware was first seen on April 4, 2018, with a second variant emerging on April 10.“

Talos researchers have discovered that malicious code intentionally avoids IP addresses associated with anonymous services. Behind-the-scenes attackers use multiple pcloud.com hard-coded accounts to store confidential data, and the stolen information is not encrypted, leaving anyone accessing these account credentials to obtain compromised data.

“This malware should be considered a wakeup call to encrypted messaging systems users. Features which are not clearly explained and bad defaults can put in jeopardy their privacy.” concludes Talos experts.

“When compared with the large bot networks used by large criminal enterprises, this threat can be considered almost insignificant.” 

“The malware samples analysed are not particularly sophisticated but they are efficient. There are no persistence mechanisms, meaning victims execute the malware every time, but not after reboots”.

Source: talosintelligence

Related coverage

  • FIN7’s New Stealth Weapon: AnubisBackdoor Emerges in the Wild
  • Stan Ghouls Target Uzbekistan and Russia with NetSupport RAT
  • A New Crisis for CrowdStrike: A Self-Replicating Worm Has Compromised Its NPM Packages
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Telegrab Malware

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90847CVSS 9.1
    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element...
  • CVE-2026-12944CVSS 9.6
    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary...
  • CVE-2026-67399CVSS 9.3
    Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before...
  • CVE-2026-65414CVSS 9.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue...
  • CVE-2026-16338CVSS 9.9
    IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow...
  • CVE-2026-59178CVSS 9.8
    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management...
  • CVE-2026-90945CVSS 9.8
    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing...
  • CVE-2026-90942CVSS 9.6
    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private...
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco...
  • CVE-2026-76443CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.