Remote access Trojan is being distributed via download links for software or media articles on Telegram channels. The malware, dubbed FatalRAT, can be remotely executed and can perform defense evasion techniques. It can obtain system persistence, log user keystrokes, collect system information and exfiltrate data over an encrypted command-and-control channel. AT&T Alien Labs does not say how many victims have been affected by the malware, which can be downloaded and executed remotely. In February, security firm Malwarebytes found fraudsters were using Telegram’s API to steal victims’ credentials.”]
Source: https://www.govinfosecurity.com/fatalrat-exploits-telegram-to-deliver-malicious-links-a-17199