build1 publisher
Iranian spyware hides command traffic in per-victim Telegram bots and commercial object storage
NCSC, FBI and AIVD say two Iranian spyware families report to per-victim Telegram bots and exfiltrate through Vultr, Storj and Backblaze B2. Networks already allow those services, so detection has to rely on host behaviour such as new Defender exclusions.
Publishers:dev.to
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50