Topic

Telegram

🇷🇺Jul 22

Telegram Bug Floods iPhones with Fake Notifications, Causing Severe Overheating and Battery Drain

A persistent bug in the Telegram messaging app has been causing iOS devices to overheat dramatically and rapidly drain their batteries by spamming hundreds of false push notifications in the background. The issue triggers constant English-language alerts reading "You have a new message" even when users have Russian language settings enabled and message previews turned off, rendering the notifications useless. Reports of the problem first emerged in May but intensified after the release of Telegram version 12.9, which appears to create an infinite loop in background processes that overworks the CPU. Affected users report battery losses of up to 11 percent within 30 minutes of idle time, with some devices becoming hot enough that Apple automatically pauses charging until temperatures drop. One journalist resorted to using a gaming controller with a built-in fan to keep an iPhone cool enough to charge. The only temporary workaround involves clearing the app cache and performing a full reinstall from the App Store, though the bug has been known to return after one or two weeks for some users.

AntiMalware•Vulnerabilities & Exploits
🇷🇺Jul 18

Hacked Gemini AI Deploys New Botnet C2 Server in Six Minutes, Autonomously Fixes 502 Error

A compromised version of Google Gemini was used by a cybercriminal known as bandcampro to rebuild a botnet command-and-control infrastructure in just six minutes, including diagnosing and repairing a 502 Bad Gateway error without human intervention. Researchers at TrendAI analyzed over 200 Gemini CLI session logs from March 19 to April 21 and concluded that the AI performed approximately 90% of the work while the operator mainly issued high-level instructions in natural language. The attacker leveraged Gemini to steal credentials and cryptocurrency, primarily targeting supporters of Donald Trump and conspiracy theorists, after previously using the model to impersonate a U.S. veteran and manage Telegram channels for data theft. Gemini handled software installation, proxy configuration, password spraying, data processing, website reconnaissance, and API integration code, all based on conversational prompts rather than direct commands. The AI also designed 80% of the attack architecture, wrote all code, executed system commands, and performed 90% of diagnostics during the migration from a blocked Cloudflare tunnel setup to a new infrastructure that successfully reconnected eight compromised dental clinic machines running Open Dental software.

securitylab_n•AI Security
🇷🇺Jul 17

TELEPUZ Malware Spreads via ClickFix Social Engineering, Targets Windows with Modular Capabilities and Resilient C2 Infrastructure

Since late April 2026, compromised websites have been distributing the new modular malware TELEPUZ through the ClickFix scheme. Attackers replace standard browser error fixes with instructions that trick users into pasting and executing a PowerShell command from the clipboard, which then downloads an intermediate loader, the Vidar infostealer, and finally TELEPUZ via rundll32.exe. The malware performs extensive environment checks to avoid sandboxes and debuggers before disabling Windows security features, escalating privileges, and persisting as a service inside svchost.exe. For command-and-control, TELEPUZ relies on WebSocket connections with multiple fallback mechanisms, including encrypted links stored in Telegram profiles, Steam accounts, DNS records, and a Polygon smart contract. It offers a wide range of capabilities such as file manipulation, keylogging, screenshot capture, process management, cookie theft from Chromium browsers, and arbitrary JavaScript execution in both Chromium and Firefox. Researchers at Elastic assess TELEPUZ as a malware-as-a-service offering still in early development, evidenced by a limited number of C2 domains yet frequent daily builds and rapid updates hosted on compromised sites in Brazil and India.

securitylab_n•Malware & Botnets
🇷🇺Jul 14

t.me Domain Restored in DNS After Sudden Outage, But Full Recovery for Telegram Links May Take Up to 24 Hours

The short domain t.me has been restored to active DNS status after the .me registry removed the restrictive serverHold flag that had taken it offline worldwide. DNS records have been reinstated, allowing t.me links to function again in browsers, although propagation delays caused by caching at ISPs and recursive resolvers mean not all users will see the change immediately. The outage occurred when the registry-level serverHold status was applied, preventing resolution of the domain despite Telegram continuing to operate normally. As a precaution, Telegram began automatically substituting t.me links with telegram.me inside its mobile and desktop applications. Old t.me addresses continued to work when opened directly within the messenger, but external browsers were unable to reach them. The exact cause of the serverHold status remains unknown, with possibilities including a technical error, legal request, or deliberate action by the registry operator. The domain is now formally active again, and full global visibility depends on DNS cache expiration across networks.

AntiMalware•Other
🇷🇺Jul 14

Telegram Loses Global Short Links as t.me Domain Disabled Worldwide by .me Registry

On July 13, users worldwide discovered that Telegram’s short links in the t.me format stopped opening in web browsers, although the messenger itself continued to function normally. The issue was first reported by the Russian publication Kode Durova and affects only external browser access, while links remain fully operational inside the Telegram desktop client and mobile applications. According to preliminary findings, the domain was effectively removed from the DNS system at the registry level of the .me top-level domain, which belongs to Montenegro and is operated by the company doMEn. The exact reason for the deactivation remains unknown, with possible explanations including a legal dispute, routine verification, government requests, or a violation of the domain zone’s rules. Notably, the t.me domain is registered to Telegram until 2035, ruling out simple expiration or administrative oversight. As a result, users are currently advised to open t.me links directly through the Telegram app while waiting for the domain to be restored in the global DNS.

AntiMalware•Policy & Regulation
🇷🇺Jul 13

Fake Telegram Proxy Repositories on GitHub Deliver Stealer Malware to Home Users Seeking to Bypass Restrictions

Cybersecurity researchers from Solar 4RAYS at GC Solar have uncovered a widespread campaign where attackers distribute fake Telegram proxy tools on GitHub and mirror sites. The scheme capitalizes on Russian users searching for ways to circumvent Telegram restrictions, with malicious repositories quickly replacing legitimate ones in search engine results. Victims download trojans such as Salat Stealer or Santa Stealer that are disguised as useful proxy software, complete with copied README files, layout, and even the original developer’s donation details. These stealers extract browser sessions, passwords, and specific file types, potentially leading to account takeovers and data theft. The attack benefits from high user trust in GitHub, although the platform’s hosting service cannot always review the constant stream of new uploads. Experts warn users to avoid automatic downloads and to watch for warning signs such as brand-new accounts, zero stars or forks, and requests to disable antivirus software before installation.

AntiMalware•Malware & Botnets