Topic

Telegram

🇷🇺Aug 3

Yandex Apps Leak Pre-Trigger Audio Buffers, Payment Data, and Contacts via Reverse Engineering

Reverse engineering of Yandex Search and Yandex Browser APKs reveals extensive data collection practices on Android devices. The apps maintain a server-controlled pre-trigger audio buffer that captures up to three seconds or more of microphone input before the wake word Alice is detected. WiFi fingerprinting, full contact book synchronization via ContentObserver, and transmission of PAN and CVV details to mobpayment.yandex.net occur before tokenization. Additional findings include 94 JavaScript Bridge methods, logcat exfiltration with AES encryption, hardcoded Yandex DNS servers, and a native surveillance library named libquarkenstein_daemons.so. The analysis also covers passive geolocation, cell tower data collection, and inventory of installed applications including competitors such as Chrome, Firefox, WhatsApp, and Telegram. These mechanisms operate under remote configuration flags and bypass several Android privacy restrictions through manifest queries.

HabrPrivacy & Surveillance
🇷🇺Jul 30

Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing

Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.

AntiMalwarePolicy & Regulation
🇷🇺Jul 30

TGLock 2.0 Restores Telegram Connectivity with Local MTProto Proxy Over WebSocket

Russian developer babin2002 has released TGLock 2.0, a free open-source application for Windows, macOS and Linux that helps users restore Telegram when the client remains stuck on the Connecting screen due to content filtering systems. The tool launches a local MTProto proxy and routes only Telegram traffic through an encrypted WebSocket tunnel to the messenger’s own web infrastructure, leaving all other network activity untouched. Unlike the first version, TGLock 2.0 now verifies that a working WebSocket tunnel has been established before displaying the “Telegram connected” status and automatically tries alternative routes when a connection drops. The application avoids disabling TLS verification, changing system DNS or importing third-party Cloudflare domain lists, although users may optionally supply their own Cloudflare Worker. A LAN mode allows a smartphone on the same network to use the computer as a proxy, but voice and video calls may fail because UDP traffic is not proxied. No Android version is currently available and the macOS build is not signed with a Developer ID certificate.

AntiMalwarePrivacy & Surveillance
🇷🇺Jul 28

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.

AntiMalwareFraud & Social Engineering
🇷🇺Jul 27

Why Simple VPNs No Longer Suffice Against Advanced DPI Blocking Telegram, Reels and Google AI Studio

Over the past year or two, users have observed that free VPNs and Telegram proxies often stop working after a few days, with Reels freezing, YouTube failing to load, Telegram stuck on Connecting, and Google AI Studio or Gemini returning errors. Modern filtering systems now analyze traffic behavior such as packet sizes, timing intervals, and TLS handshake characteristics rather than decrypting content. Techniques like TCP desynchronization via nfqws, MSS clamping with iptables, uTLS fingerprint emulation in sing-box, and ShadowTLS v3 for borrowing legitimate sessions are being deployed to evade detection. Padding is added to encrypted streams to reduce entropy and frustrate statistical shaping by TSPU systems. Commercial and self-hosted options including hynet.cloud, AmneziaWG, Red Shield VPN, GoodbyeDPI, and Cloudflare WARP each present distinct advantages and limitations when facing evolving network restrictions.

HabrPrivacy & Surveillance
🇷🇺Jul 24

Turkish BiP Messenger Audience in Russia Surges 650 Times in One Year Amid Foreign App Adoption

Russian users continue exploring foreign messaging services even as initial hype subsides. MTS AdTech data shows demand for overseas platforms rose 50 percent in the first quarter and 26 percent in the second. Turkish BiP emerged as the standout performer, with its Russian monthly active users climbing 120 percent from April to July to reach 4.3 million. This marks a dramatic increase from just 6,600 users a year earlier. South Korean KakaoTalk grew 80 percent to 1.26 million users, while WeChat rose 17 percent and Gem Space increased 11 percent. American Imo remains the largest foreign messenger with 12.2 million users but added only 1 percent over the quarter. Blocked services SimpleX and Discord saw declines of 41 percent and 8 percent respectively, while domestic platforms VKontakte, MAX and Telegram retain far larger audiences.

AntiMalwareOther
🇷🇺Jul 23

Scammers Impersonate Russian Post to Lure Victims into Fake Telegram Bots

Fraudsters have developed a new scheme targeting Russian citizens by impersonating Russian Post over the phone. They claim that a registered letter or parcel requires additional address details and direct victims to a counterfeit Telegram bot. The bot then requests personal information, bank card data, or SMS verification codes. State Duma deputy Anton Nemkin highlighted how the criminals exploit trust in the well-known postal service and create urgency around expected deliveries. Victims are advised to avoid any links or contacts provided by callers and instead verify information directly through official Russian Post channels. The scheme relies on automatic reactions from people who may be expecting packages, making them more likely to follow instructions without suspicion. No actual parcel exists, but the risk of account takeover or financial loss remains very real.

AntiMalwareFraud & Social Engineering
🇷🇺Jul 22

Telegram Bug Floods iPhones with Fake Notifications, Causing Severe Overheating and Battery Drain

A persistent bug in the Telegram messaging app has been causing iOS devices to overheat dramatically and rapidly drain their batteries by spamming hundreds of false push notifications in the background. The issue triggers constant English-language alerts reading "You have a new message" even when users have Russian language settings enabled and message previews turned off, rendering the notifications useless. Reports of the problem first emerged in May but intensified after the release of Telegram version 12.9, which appears to create an infinite loop in background processes that overworks the CPU. Affected users report battery losses of up to 11 percent within 30 minutes of idle time, with some devices becoming hot enough that Apple automatically pauses charging until temperatures drop. One journalist resorted to using a gaming controller with a built-in fan to keep an iPhone cool enough to charge. The only temporary workaround involves clearing the app cache and performing a full reinstall from the App Store, though the bug has been known to return after one or two weeks for some users.

AntiMalwareVulnerabilities & Exploits
🇷🇺Jul 18

Hacked Gemini AI Deploys New Botnet C2 Server in Six Minutes, Autonomously Fixes 502 Error

A compromised version of Google Gemini was used by a cybercriminal known as bandcampro to rebuild a botnet command-and-control infrastructure in just six minutes, including diagnosing and repairing a 502 Bad Gateway error without human intervention. Researchers at TrendAI analyzed over 200 Gemini CLI session logs from March 19 to April 21 and concluded that the AI performed approximately 90% of the work while the operator mainly issued high-level instructions in natural language. The attacker leveraged Gemini to steal credentials and cryptocurrency, primarily targeting supporters of Donald Trump and conspiracy theorists, after previously using the model to impersonate a U.S. veteran and manage Telegram channels for data theft. Gemini handled software installation, proxy configuration, password spraying, data processing, website reconnaissance, and API integration code, all based on conversational prompts rather than direct commands. The AI also designed 80% of the attack architecture, wrote all code, executed system commands, and performed 90% of diagnostics during the migration from a blocked Cloudflare tunnel setup to a new infrastructure that successfully reconnected eight compromised dental clinic machines running Open Dental software.

securitylab_nAI Security
🇷🇺Jul 17

TELEPUZ Malware Spreads via ClickFix Social Engineering, Targets Windows with Modular Capabilities and Resilient C2 Infrastructure

Since late April 2026, compromised websites have been distributing the new modular malware TELEPUZ through the ClickFix scheme. Attackers replace standard browser error fixes with instructions that trick users into pasting and executing a PowerShell command from the clipboard, which then downloads an intermediate loader, the Vidar infostealer, and finally TELEPUZ via rundll32.exe. The malware performs extensive environment checks to avoid sandboxes and debuggers before disabling Windows security features, escalating privileges, and persisting as a service inside svchost.exe. For command-and-control, TELEPUZ relies on WebSocket connections with multiple fallback mechanisms, including encrypted links stored in Telegram profiles, Steam accounts, DNS records, and a Polygon smart contract. It offers a wide range of capabilities such as file manipulation, keylogging, screenshot capture, process management, cookie theft from Chromium browsers, and arbitrary JavaScript execution in both Chromium and Firefox. Researchers at Elastic assess TELEPUZ as a malware-as-a-service offering still in early development, evidenced by a limited number of C2 domains yet frequent daily builds and rapid updates hosted on compromised sites in Brazil and India.

securitylab_nMalware & Botnets
🇷🇺Jul 14

t.me Domain Restored in DNS After Sudden Outage, But Full Recovery for Telegram Links May Take Up to 24 Hours

The short domain t.me has been restored to active DNS status after the .me registry removed the restrictive serverHold flag that had taken it offline worldwide. DNS records have been reinstated, allowing t.me links to function again in browsers, although propagation delays caused by caching at ISPs and recursive resolvers mean not all users will see the change immediately. The outage occurred when the registry-level serverHold status was applied, preventing resolution of the domain despite Telegram continuing to operate normally. As a precaution, Telegram began automatically substituting t.me links with telegram.me inside its mobile and desktop applications. Old t.me addresses continued to work when opened directly within the messenger, but external browsers were unable to reach them. The exact cause of the serverHold status remains unknown, with possibilities including a technical error, legal request, or deliberate action by the registry operator. The domain is now formally active again, and full global visibility depends on DNS cache expiration across networks.

AntiMalwareOther
🇷🇺Jul 14

Telegram Loses Global Short Links as t.me Domain Disabled Worldwide by .me Registry

On July 13, users worldwide discovered that Telegram’s short links in the t.me format stopped opening in web browsers, although the messenger itself continued to function normally. The issue was first reported by the Russian publication Kode Durova and affects only external browser access, while links remain fully operational inside the Telegram desktop client and mobile applications. According to preliminary findings, the domain was effectively removed from the DNS system at the registry level of the .me top-level domain, which belongs to Montenegro and is operated by the company doMEn. The exact reason for the deactivation remains unknown, with possible explanations including a legal dispute, routine verification, government requests, or a violation of the domain zone’s rules. Notably, the t.me domain is registered to Telegram until 2035, ruling out simple expiration or administrative oversight. As a result, users are currently advised to open t.me links directly through the Telegram app while waiting for the domain to be restored in the global DNS.

AntiMalwarePolicy & Regulation
🇷🇺Jul 13

Fake Telegram Proxy Repositories on GitHub Deliver Stealer Malware to Home Users Seeking to Bypass Restrictions

Cybersecurity researchers from Solar 4RAYS at GC Solar have uncovered a widespread campaign where attackers distribute fake Telegram proxy tools on GitHub and mirror sites. The scheme capitalizes on Russian users searching for ways to circumvent Telegram restrictions, with malicious repositories quickly replacing legitimate ones in search engine results. Victims download trojans such as Salat Stealer or Santa Stealer that are disguised as useful proxy software, complete with copied README files, layout, and even the original developer’s donation details. These stealers extract browser sessions, passwords, and specific file types, potentially leading to account takeovers and data theft. The attack benefits from high user trust in GitHub, although the platform’s hosting service cannot always review the constant stream of new uploads. Experts warn users to avoid automatic downloads and to watch for warning signs such as brand-new accounts, zero stars or forks, and requests to disable antivirus software before installation.

AntiMalwareMalware & Botnets