Talos has seen the emergence of a malware that collects cache and key files from end-to-end encrypted instant messaging service Telegram. This malware was first seen on April 4, 2018, with a second variant emerging on April 10. The malware is mainly targeting Russian-speaking victims, and is intentionally avoiding IP addresses related with anonymizer services. The author posted several YouTube videos with instructions on how to use the Telegram collected files to hijack Telegram sessions and how to package it for distribution. Talos believes with high confidence the author of the malware is the same.”]
Source: https://blog.talosintelligence.com/2018/05/telegrab.html

