The rise of TeleBots: Analyzing disruptive KillDisk attacks
ID: 7f1b0e65-56c4-4b9b-96ae-bc03ec636cba
STIX ID: report--7f1b0e65-56c4-4b9b-96ae-bc03ec636cba
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2016-12-14
Last Modified Date: 2016-12-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
An in-depth analysis of TeleBots and associated malware activities (including KillDisk, Python/TeleBot, and VBS backdoors), outlining infection chains, tool evolution from BlackEnergy, data theft and credential harvesting capabilities, covert C2 channels (Telegram Bot API and other services), and IoCs to illustrate a sophisticated, targeted cybersabotage campaign against critical Ukrainian sectors.
