{"id":3646,"date":"2021-09-09T14:47:21","date_gmt":"2021-09-09T19:47:21","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3646"},"modified":"2021-09-09T14:47:22","modified_gmt":"2021-09-09T19:47:22","slug":"toxiceye-rat-takes-use-of-telegram-communication","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/","title":{"rendered":"ToxicEye RAT &#8211; Takes use of telegram communication"},"content":{"rendered":"\n<p>Cybercriminals are making use of the Telegram API as a means of communication to their C2, thanks to the infrastructure capabilities of this social network, as it is a legitimate, stable service, a service that is not detectable as malicious by antimalware engines or network tools , allows attackers to carry out their malicious activities with ToxicEye RAT while maintaining your anonymity.<\/p>\n\n\n\n<p>Check Point published an extensive blog post about the new RAT. Its researchers stated that around 130 attacks executed with the new Trojan have been detected in the wild over the past three months. Perhaps part of the reason that the bad actors who operate the ToxicEye RAT have resorted to abusing Telegram on all platforms is the recent surge in popularity that Telegram had. That increase in users was largely due to some of the changes that were made to the way WhatsApp shares information with its parent company on Facebook.<\/p>\n\n\n\n<p>ToxicEye abuses the Telegram platform and uses Telegram to provide command and control functionality for malware. Check Point pointed out a few factors that make Telegram particularly attractive to bad actors, including the fact that an account only requires a mobile phone number, as well as the fact that the way Telegram communicates may allow hackers. Computer scientists exfiltrate information from their victims with relative ease.<\/p>\n\n\n\n<p>The new RAT spreads using the usual method: malicious phishing emails that have an executable file attached which is why it is important not to trust the suspicious emails you receive. Once the executable is opened by the victim, ToxicEye RAT is deployed and can perform a surprisingly versatile range of malicious tasks. Those tasks include data extraction, file manipulation, manipulation of running processes on the victim&#8217;s system, recording audio and video in the presence of available hardware, and even file encryption.<\/p>\n\n\n\n<p>The best thing to avoid this threat as we saw before is to have a little discretion and keep a cool head, so we cannot be fooled so easily by these cybercriminals since this type of threat always requires interaction with users.<\/p>\n\n\n\n<p>See more:<br><a href=\"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/\">FatalRAT \u2013 Trojan that spreads via Telegram<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/oscorp-malware-that-attacks-android\/\">Oscorp Malware that attacks Android<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are making use of the Telegram API as a means of communication to their C2, thanks to the infrastructure capabilities of this social network, as it is a legitimate, stable service, a service that is not detectable as malicious by antimalware engines or network tools , allows attackers to carry out their malicious activities [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3647,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3646","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-09T19:47:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-09T19:47:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1327\" \/>\n\t<meta property=\"og:image:height\" content=\"788\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"ToxicEye RAT &#8211; Takes use of telegram communication\",\"datePublished\":\"2021-09-09T19:47:21+00:00\",\"dateModified\":\"2021-09-09T19:47:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/\"},\"wordCount\":364,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/ToxicEye.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/\",\"name\":\"ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/ToxicEye.jpg\",\"datePublished\":\"2021-09-09T19:47:21+00:00\",\"dateModified\":\"2021-09-09T19:47:22+00:00\",\"description\":\"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/ToxicEye.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/ToxicEye.jpg\",\"width\":1327,\"height\":788},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/toxiceye-rat-takes-use-of-telegram-communication\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ToxicEye RAT &#8211; Takes use of telegram communication\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog","description":"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/","og_locale":"es_MX","og_type":"article","og_title":"ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog","og_description":"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......","og_url":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-09-09T19:47:21+00:00","article_modified_time":"2021-09-09T19:47:22+00:00","og_image":[{"width":1327,"height":788,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"ToxicEye RAT &#8211; Takes use of telegram communication","datePublished":"2021-09-09T19:47:21+00:00","dateModified":"2021-09-09T19:47:22+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/"},"wordCount":364,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/","url":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/","name":"ToxicEye RAT - Takes use of telegram communication - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg","datePublished":"2021-09-09T19:47:21+00:00","dateModified":"2021-09-09T19:47:22+00:00","description":"Today we will see a threat that uses Telegram as a means of communication with its control server which is known as ToxicEye Rat......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/ToxicEye.jpg","width":1327,"height":788},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/toxiceye-rat-takes-use-of-telegram-communication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"ToxicEye RAT &#8211; Takes use of telegram communication"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3646"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3646\/revisions"}],"predecessor-version":[{"id":3721,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3646\/revisions\/3721"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3647"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}