Topic
Telegram

Hacked Gemini AI Deploys New Botnet C2 Server in Six Minutes, Autonomously Fixes 502 Error
AI Security
TELEPUZ Malware Spreads via ClickFix Social Engineering, Targets Windows with Modular Capabilities and Resilient C2 Infrastructure
Malware & Botnets
t.me Domain Restored in DNS After Sudden Outage, But Full Recovery for Telegram Links May Take Up to 24 Hours
OtherTelegram Loses Global Short Links as t.me Domain Disabled Worldwide by .me Registry
On July 13, users worldwide discovered that Telegram’s short links in the t.me format stopped opening in web browsers, although the messenger itself continued to function normally. The issue was first reported by the Russian publication Kode Durova and affects only external browser access, while links remain fully operational inside the Telegram desktop client and mobile applications. According to preliminary findings, the domain was effectively removed from the DNS system at the registry level of the .me top-level domain, which belongs to Montenegro and is operated by the company doMEn. The exact reason for the deactivation remains unknown, with possible explanations including a legal dispute, routine verification, government requests, or a violation of the domain zone’s rules. Notably, the t.me domain is registered to Telegram until 2035, ruling out simple expiration or administrative oversight. As a result, users are currently advised to open t.me links directly through the Telegram app while waiting for the domain to be restored in the global DNS.
Fake Telegram Proxy Repositories on GitHub Deliver Stealer Malware to Home Users Seeking to Bypass Restrictions
Cybersecurity researchers from Solar 4RAYS at GC Solar have uncovered a widespread campaign where attackers distribute fake Telegram proxy tools on GitHub and mirror sites. The scheme capitalizes on Russian users searching for ways to circumvent Telegram restrictions, with malicious repositories quickly replacing legitimate ones in search engine results. Victims download trojans such as Salat Stealer or Santa Stealer that are disguised as useful proxy software, complete with copied README files, layout, and even the original developer’s donation details. These stealers extract browser sessions, passwords, and specific file types, potentially leading to account takeovers and data theft. The attack benefits from high user trust in GitHub, although the platform’s hosting service cannot always review the constant stream of new uploads. Experts warn users to avoid automatic downloads and to watch for warning signs such as brand-new accounts, zero stars or forks, and requests to disable antivirus software before installation.