The Bot Census: A Year Inside Malware's Telegram Ecosystem
Over the past year, I collected thousands of Telegram bot tokens from VirusTotal and used them to study how threat actors abuse Telegram. This talk presents insights gathered from this unique dataset and examines how the role of Telegram within the malware ecosystem is changing over time. It also discusses the practical challenges of collecting, validating, and monitoring malicious Telegram bots at scale.
Building on last year's hack.lu presentation Compromising Threat Actor Communications by Ben (@polygonben), this talk explores what can be learned from observing thousands of malicious Telegram bots at scale.
Over the past year I collected a steadily growing collection of unique Telegram bot tokens from malware samples published on VirusTotal, now spanning many thousands of distinct bots.
Telegram has become a popular platform for malware operators, but little is known about the ecosystem as a whole. Is it still growing as a malware communication channel, or has its popularity started to decline?
This presentation introduces the collection and analysis pipeline used to identify and monitor these bots at scale. More importantly, it presents the findings gathered from the dataset, and discusses the operational challenges of studying malicious Telegram infrastructure, including the limitations researchers run into when analyzing these systems.
Manuel is a security researcher driven by a passion to make threat actors’ lives harder. He works as a Cyber Security Analyst at dmTECH and also takes on freelance projects. When he’s off the clock, Manuel solves CTF challenges, writes blog posts for mboll.eu, and relaxes with a beer at the pub while philosophizing about the latest malware.