TelB
- First seen
- 2021-05-01 00:00:00
- Malware type
- credential-stealer, spyware, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 15:05:46
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Telb_Auto (yara-rule)
Reports & references
- research.checkpoint.com — Rampant Kitten An Iranian Espionage Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Telb (report)