Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Swellchain to Shut Down Native Network on June 15, Shifts Focus to AI Platform on Hyperliquid

June 13, 2026

Bitcoin Network Is Set to Experience One of the Largest Mining Difficulty Drops in Its History Today

June 13, 2026

SEC rule rollback could unlock tokenized U.S. stock trading in DeFi

June 13, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Telegram Zero-Day Exploited by Crypto-Miners
Telegram Zero-Day Exploited by Crypto-Miners
Security and Privacy

Telegram Zero-Day Exploited by Crypto-Miners

September 5, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Russian cyber-criminals have been exploiting a zero-day flaw in popular comms service Telegram, allowing them to remotely install new malware which could be used as a backdoor or a means to deliver crypto-mining software, according to Kaspersky Lab.

The security vendor claimed that the vulnerability had been actively exploited since March 2017 to help mine crypto-currency including Monero and Zcash.

The zero-day was present in the desktop version of the encrypted comms app. It used a so-called “right-to-left override” (RLO) technique whereby attackers use a hidden Unicode character to reverse the characters in a file name.

Thus, malicious JavaScript file “gnp.js” becomes “sj.png,” tricking users into believing the prepared malware is actually a harmless image file.

The zero-day itself was identified as being exploited to deliver digital currency miners such as CryptoNight and Equihash. This type of malware typically lies hidden on a victim’s machine, silently using up compute power to mine valuable crypto-currency.

Another attack starting with the zero-day exploit installed a backdoor using the Telegram API as C&C protocol, allowing the attackers to gain remote access to the victim’s machine. After installation, the malware operated silently, allowing the hackers to stay unnoticed and potentially install spyware tools, Kaspersky Lab claimed.

“The popularity of instant messenger services is incredibly high, and it’s extremely important that developers provide proper protection for their users so that they don’t become easy targets for criminals,” argued the vendor’s malware analyst, Alexey Firsh.

“We have found several scenarios of this zero-day exploitation that, besides general malware and spyware, was used to deliver mining software — such infections have become a global trend that we have seen throughout the last year. Furthermore, we believe there were other ways to abuse this zero-day vulnerability.”

See also  Telegram asserts control over TON blockchain, driving momentum

Fortunately, the vulnerability has now been closed after Telegram was notified, but Kaspersky Lab urged users not to download or open unknown files from untrusted sources.

Source link

Cryptominers exploited Telegram ZeroDay
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Crypto groups sue SEC, claiming overreach in new dealer rule definition

April 23, 2024

Bitcoin Miners Posted Record Profits in 2Q as HPC Push Accelerated, JPMorgan Says

October 7, 2025

How to Leverage Gen Z Consumer Patterns in Web3 Advertising

August 26, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Swellchain to Shut Down Native Network on June 15, Shifts Focus to AI Platform on Hyperliquid

June 13, 2026

Bitcoin Network Is Set to Experience One of the Largest Mining Difficulty Drops in Its History Today

June 13, 2026

SEC rule rollback could unlock tokenized U.S. stock trading in DeFi

June 13, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,408.001.38%
  • ethereumEthereum(ETH)$1,679.670.88%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$609.721.03%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.151.59%
  • solanaSolana(SOL)$68.833.12%
  • tronTRON(TRX)$0.3170520.55%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.68%
  • dogecoinDogecoin(DOGE)$0.0878352.19%