😈
Telegraph as a Malware Command-and-Control Resolver 😈
What this malware is doing▶️This malware uses
telegra.ph, a publishing platform operated by
Telegram, as a
dead-drop resolver for its command-and-control (C2) infrastructure.
▶️Instead of hard-coding an IP address or domain, the malware retrieves a public Telegraph page and extracts configuration data from it at runtime.
In this case, the malware fetches a fixed URL:
https://telegra.ph/3657468-10-13
It then parses the HTML and looks specifically for this tag:
<meta property="og:description" content="...">
The value of
og:description is expected to contain
Base64-encoded data, which is then
XOR-decrypted to produce the actual C2 host (IP or domain).
How it works step by step1️⃣
HTTP request to a trusted platform The malware performs a normal HTTPS GET request to
telegra.ph, a domain that is:
▶️widely trusted
▶️rarely blocked
▶️commonly allowed through firewalls
2️⃣
Extraction of metadata instead of page contentRather than parsing the visible page body, the malware reads the Open Graph metadata (
og:description), which is usually ignored by scanners.
3️⃣
Multi-layer decoding▶️The content is split into tokens
▶️Each token is Base64-decoded
▶️The decoded bytes are XOR-decrypted using a static key
▶️The result is concatenated into a string used as
HOST4️⃣
Dynamic C2 resolution▶️The resolved host is used for a TCP reverse connection
▶️The malware never stores the C2 address statically
5️⃣
Remote kill / disable▶️If the Telegraph page is edited (e.g., changed to
content="1"), the resolver breaks
▶️This immediately disables all deployed samples without updating them
Why attackers use Telegraph for thisThis technique is intentionally designed for
resilience and stealth:
▶️
C2 infrastructure can be changed instantly▶️
No redeployment of malware is required▶️
Indicators of compromise are minimized▶️
Traffic blends in with legitimate web browsing▶️
Trusted domains evade many security controls📖 This is a textbook example of a
dead-drop C2 resolver.
This malware component functions as:▶️
Stage-2 loader▶️
Backdoor client▶️
Dead-drop resolver▶️
Fileless configuration fetcher❌ It is
not persistent by itself and relies on external control.
🔗
Channel: https://t.me/+ZcWpNaZALkIxYjUy