What this malware is doing
▶️This malware uses telegra.ph, a publishing platform operated by Telegram, as a dead-drop resolver for its command-and-control (C2) infrastructure.
▶️Instead of hard-coding an IP address or domain, the malware retrieves a public Telegraph page and extracts configuration data from it at runtime.
In this case, the malware fetches a fixed URL:
https://telegra.ph/3657468-10-13
It then parses the HTML and looks specifically for this tag:
<meta property="og:description" content="...">
The value of
og:description is expected to contain Base64-encoded data, which is then XOR-decrypted to produce the actual C2 host (IP or domain).How it works step by step
1️⃣HTTP request to a trusted platform
The malware performs a normal HTTPS GET request to telegra.ph, a domain that is:
▶️widely trusted
▶️rarely blocked
▶️commonly allowed through firewalls
2️⃣ Extraction of metadata instead of page content
Rather than parsing the visible page body, the malware reads the Open Graph metadata (
og:description), which is usually ignored by scanners.3️⃣ Multi-layer decoding
▶️The content is split into tokens
▶️Each token is Base64-decoded
▶️The decoded bytes are XOR-decrypted using a static key
▶️The result is concatenated into a string used as
HOST4️⃣ Dynamic C2 resolution
▶️The resolved host is used for a TCP reverse connection
▶️The malware never stores the C2 address statically
5️⃣ Remote kill / disable
▶️If the Telegraph page is edited (e.g., changed to
content="1"), the resolver breaks▶️This immediately disables all deployed samples without updating them
Why attackers use Telegraph for this
This technique is intentionally designed for resilience and stealth:
▶️C2 infrastructure can be changed instantly
▶️No redeployment of malware is required
▶️Indicators of compromise are minimized
▶️Traffic blends in with legitimate web browsing
▶️Trusted domains evade many security controls
📖 This is a textbook example of a dead-drop C2 resolver.
This malware component functions as:
▶️Stage-2 loader
▶️Backdoor client
▶️Dead-drop resolver
▶️Fileless configuration fetcher
❌ It is not persistent by itself and relies on external control.
🔗 Channel: https://t.me/+ZcWpNaZALkIxYjUy