TGViewer
C.I.T. Security C.I.T. Security @citsecurity · 8.96K subscribers
Post #9635 1.43K
telegraph malware.py6.3 KB
😈 Telegraph as a Malware Command-and-Control Resolver 😈

What this malware is doing

▶️This malware uses telegra.ph, a publishing platform operated by Telegram, as a dead-drop resolver for its command-and-control (C2) infrastructure.

▶️Instead of hard-coding an IP address or domain, the malware retrieves a public Telegraph page and extracts configuration data from it at runtime.

In this case, the malware fetches a fixed URL:

https://telegra.ph/3657468-10-13


It then parses the HTML and looks specifically for this tag:

<meta property="og:description" content="...">


The value of og:description is expected to contain Base64-encoded data, which is then XOR-decrypted to produce the actual C2 host (IP or domain).

How it works step by step

1️⃣HTTP request to a trusted platform
The malware performs a normal HTTPS GET request to telegra.ph, a domain that is:

▶️widely trusted
▶️rarely blocked
▶️commonly allowed through firewalls

2️⃣ Extraction of metadata instead of page content

Rather than parsing the visible page body, the malware reads the Open Graph metadata (og:description), which is usually ignored by scanners.

3️⃣ Multi-layer decoding

▶️The content is split into tokens
▶️Each token is Base64-decoded
▶️The decoded bytes are XOR-decrypted using a static key
▶️The result is concatenated into a string used as HOST

4️⃣ Dynamic C2 resolution

▶️The resolved host is used for a TCP reverse connection
▶️The malware never stores the C2 address statically

5️⃣ Remote kill / disable

▶️If the Telegraph page is edited (e.g., changed to content="1"), the resolver breaks
▶️This immediately disables all deployed samples without updating them


Why attackers use Telegraph for this

This technique is intentionally designed for resilience and stealth:

▶️C2 infrastructure can be changed instantly
▶️No redeployment of malware is required
▶️Indicators of compromise are minimized
▶️Traffic blends in with legitimate web browsing
▶️Trusted domains evade many security controls

📖 This is a textbook example of a dead-drop C2 resolver.

This malware component functions as:

▶️Stage-2 loader
▶️Backdoor client
▶️Dead-drop resolver
▶️Fileless configuration fetcher

❌ It is not persistent by itself and relies on external control.

🔗 Channel: https://t.me/+ZcWpNaZALkIxYjUy
  • 👍 2
  • ❤ 1
More from @citsecurity
  1. Oct 3, 2026DeepSeek выпустила Harness для macOS и Windows 🤩 По факту это открытая альтернатива Claud…
  2. Oct 2, 2026This is from us. Windows Installer but AnyOS Crack. You know where to get it! Don't bother…
  3. Oct 2, 2026Metasploit Pro Keygen Setup: - Install Metasploit Pro - Use the keygen and follow the step…
  4. Oct 2, 2026Evilginx Pro 4.3.2 Keygen NOTE: - The keygen works for the server option, the "client" one…
  5. Sep 29, 2026@voice_platform_bot — позволяет идентифицировать платформу Telegram по отправленному голос…
  6. Sep 29, 2026Продолжаю развивать легальную базу для российских OSINT-исследователей на t.me/project_OSI…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →