In October 2017, we learned of a vulnerability in Telegram Messengers Windows client that was being exploited in the wild. It involves the use of a classic right-to-left override attack when a user sends files over the messenger service. The attacker sends the message, and surprise! the recipient sees an incoming PNG image file instead of a JS file. If the user clicks on Run, the malicious file is launched and the attacker takes control of the system.”]
Source: https://securelist.com/zero-day-vulnerability-in-telegram/83800/