TeleBot

First seen
2017-01-01 00:00:00
Malware type
trojan
Profile updated
2026-07-07 12:44:46

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:ua

Context

TeleBot is an Android trojan that uses Telegram's bot API for command and control operations. It primarily targets governmental and financial sectors, with confirmed activity in Ukraine.

Reports & references

  • ESET — Rise Telebots Analyzing Disruptive Killdisk Attacks (report)
  • ESET — Telebots Back Supply Chain Attacks Against Ukraine (report)
  • secureworks.com — Iron Viking (report)
  • blackberry.com — Report Old Dogs New Tricks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Telebot (report)

External references