
Tracking Cybercrime on Telegram
Source: YouTube · John Hammond · published Feb 26, 2024 · 23:28
The video demonstrates how info stealer malware is publicly available on platforms like GitHub and how it's used to steal sensitive data from victims 0:00. The presenter explores malware analysis techniques and shows how this malicious software can steal passwords, cookies, browser history, Wi-Fi passwords, and more, sending the data to threat actors via platforms like Discord and Telegram 0:05-0:27.
Key Takeaways:
• Info stealer malware is publicly available on GitHub and even distributed as legitimate packages through official repositories like PyPI 0:05-0:56
• Malware typically sends stolen data to threat actors through Telegram or Discord channels 1:01-1:27
• Security researchers can use tools like Flare to monitor the dark web and illicit networks for threats and stolen information 2:04-2:52
• By extracting Telegram bot tokens and chat IDs from malware, analysts can use tools like TeleTracker to interact with and potentially disrupt malicious campaigns 10:06-11:00
The presenter analyzes a "Red Trace" malware sample that reveals itself to be ransomware communicating through Telegram, demonstrating the importance of understanding how malware exfiltrates data and communicates with threat actors 14:57-21:03.
Sources:
- 0:00-0:27 Introduction to info stealer malware and its public availability
- 1:01-1:27 How malware sends stolen data to Telegram
- 2:04-2:52 Using Flare for threat hunting
- [10:06-11:00](https://www.youtube.com/watch?v=_GD5m
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
this is info stealer malware out and available on the public Internet it's literally on GitHub it will steal computer information exfiltrate Discord tokens grab passwords cookies session information history take screenshots Wi-Fi passwords and more and this is supposedly another tool that hacks into your camera and computer webcam malicious software like this is all over the public internet and it gets shared and spread around by threat actors adverse series and cyber criminals and they even get it into code like libraries and modules stuff used to write other software like look at this this Library HTTP current this was literally a module that was available on piie the official python package index and Library where others could download code to use in their own applications projects and …