HEAVYGRAM uses Telegram bots and groups as C2 to control Windows devices and spy on journalists and Iranian dissidents.
A high-severity Telegram Desktop flaw allowed malicious JavaScript in bot-created buttons to steal chat content when conversations were exported as HTML.
Saving video, converting a file or extracting audio from a video are other very common reasons people seek out a new bot.
A flaw in Telegram Desktop allowed specially crafted bot messages to execute JavaScript in HTML chat exports and expose ...
A Telegram Desktop flaw lets bots inject JavaScript into exported chats, enabling data theft and page manipulation.