Attackers Planted a Telegram-Powered Backdoor Across Fake Pyrogram Packages (opens in new tab)
A threat actor targeted Telegram bot developers adopting the popular 'pyrogram' package on PyPI over the course of six months starting November 2025, in Operation Navy Ghost. This malware is a complete backdoor on servers where infected bots are operated, and uses Telegram itself for C2 and data exfiltration. Learn how it works, how it sneaks by most scanners, and how to detect infections.
Read the original article