Cybersecurity

Kaspersky uncovers a global Telegram malware campaign targeting fintech users

Hackers used Telegram to spread spyware targeting users and businesses in the fintech and trading industries

A targeted attack on the fintech sector

The Kaspersky research team has recently revealed a global malware campaign in which cybercriminals used Telegram to distribute spyware. This malware, a sophisticated Trojan, is designed to steal sensitive data such as passwords and take control of devices for espionage purposes, targeting both individuals and companies in the fintech and trading sectors.

Who’s behind the attack: the DeathStalker group

The campaign appears linked to DeathStalker, an Advanced Persistent Threat (APT) actor offering hack-for-hire and financial intelligence services. During the latest attack observed by Kaspersky, DeathStalker attempted to infect victims with DarkMe malware, a remote access Trojan (RAT) capable of stealing information and executing commands from a remote server.

Victims: Telegram users in trading and fintech channels

Hackers targeted Telegram channels frequented by enthusiasts and professionals in trading and fintech. This campaign spanned over 20 countries across Europe, Asia, Latin America, and the Middle East.

The infection process: DarkMe malware in action

The infection chain analysis revealed that attackers used malicious archives like RAR or ZIP, attaching them to Telegram posts. Within these archives, seemingly harmless files with extensions like .LNK, .com, and .cmd trigger the infection, leading to the installation of the DarkMe malware.

Telegram as a discreet attack vector

According to Maher Yamout, a Kaspersky expert, cybercriminals use Telegram channels to bypass security checks: “Using messaging platforms like Telegram builds trust, leading victims to download malware without security warnings, which are less frequent compared to standard internet downloads.”

DeathStalker’s hiding strategy

DeathStalker employs advanced techniques to hide traces: it deletes files and tools used during the attack and enlarges the malware size to evade detection, simulating activities of other APT groups.

Kaspersky’s security advice

To mitigate risks, Kaspersky recommends:

  • Installing trusted security solutions
  • Staying informed about new attack techniques
  • Providing full cyber threat visibility for InfoSec teams
  • Investing in advanced cybersecurity training

Sign up for the newsletter. Stay updated!

We will send you periodical important communications and news about the digital world. You can unsubscribe at any time by clicking the appropriate link at the bottom of the newsletter.

Dopstart

Dopstart è il sito di Paolino Donato ma anche il suo Nickname su Internet. Dopstart è un consulente SEO. Si occupa di posizionamento nei motori di ricerca fin dal 1998. Dal 2010 ha collaborato con Google in qualità di TC per Google News italiano e Google Noticias per i Paesi di Lingua spagnola e dal 2018 come Product Expert vedi curriculum

Share
Published by
Dopstart

Recent Posts

AI and Organic Traffic: How Not to Lose Visibility

The impact of artificial intelligence on search engines and solutions for businesses Have you noticed…

5 hours ago

Google Meridian: ROI and Marketing Mix Modeling

Are you really measuring the effectiveness of your investments? Do you ever wonder if your…

1 day ago

Fashion E-commerce: Winning Strategies for 2030

Is your fashion e-commerce struggling to generate steady sales? Have you noticed advertising costs increasing…

5 days ago

Facebook Dating bets on AI: no more endless swipes, hello “Meet Cute”

Artificial intelligence transforms the online dating experiencThe arrival of the AI assistant Meta has announced a…

6 days ago

Logo for “Impresa Commercio e Distribuzione”

We designed the new logo for Impresa Commercio e Distribuzione, a brand created to communicate solidity,…

6 days ago

Gemini comes to Google Meet: the AI assistant that transforms video meetings

Real-time notes, smart summaries, and instant search: how Google is reshaping Meet with Gemini A…

1 week ago