11-29-2025, 04:12 PM
Behavior: Steals Telegram sessions and browser data.
SHA256:
Mitigation:
SHA256:
Code:
18d750df2420c9e60e251217fde331a0f4b540c270f46920213052c9fcca7c03- Block access to messaging tokens (HIPS).
- Detect suspicious network POST requests.
- Sandbox unknown EXEs.
