TelAndExt
- First seen
- 2022-01-15 00:00:00
- Malware type
- credential-stealer, spyware
- Profile updated
- 2026-07-07 15:05:49
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
Reports & references
- research.checkpoint.com — Rampant Kitten An Iranian Espionage Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Telandext (report)