TelAndExt

First seen
2022-01-15 00:00:00
Malware type
credential-stealer, spyware
Profile updated
2026-07-07 15:05:49

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.

Reports & references

  • research.checkpoint.com — Rampant Kitten An Iranian Espionage Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Telandext (report)

External references