TelB

First seen
2021-05-01 00:00:00
Malware type
credential-stealer, spyware, trojan
Family
Malware family
Profile updated
2026-07-07 15:05:46

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Telb_Auto (yara-rule)

Reports & references

  • research.checkpoint.com — Rampant Kitten An Iranian Espionage Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Telb (report)

External references