DarkWebPreDarkwebStealerScammer

The Malware Watched Back: Inside a Telegram Fraud Operation

The Malware Watched Back: Inside a Telegram Fraud Operation
Share

CyberArmor recently obtained more than 200,000 artifacts captured from computers infected by cybercriminal malware. Most documented the malware’s intended victims. One infected machine told a different story.

Its screenshots and captured activity exposed the operation of “Secret Work,” a Telegram channel with more than 1,600 subscribers. The channel sold an $80 method claiming to bypass Coinbase face verification, defeat camera and screen-detection controls, and obtain US driving licences from dark-web sources.

The most important screenshot did not merely show someone reading the channel. It captured the operator editing its pinned advertisement. Figure 1 show the advertisement posted on the Secret Work Telegram channel.

Advertisement By @jhon100xx

Figure 1: Advertisement Posted on the Secret Work Telegram Channel


That mistake transformed a malware log into a view inside a functioning cybercrime business.


The Screenshot That Changed the Investigation


Want to detect threats 8+ months earlier?

See how DarkArmor's PreBreach intelligence can protect your organization.

Book a Demo
Nguyen Nguyen
About the Author

Nguyen Nguyen

Nguyen (Founder & CEO @ CyberArmor) is a seasoned cybersecurity leader with over 15 years of experience in software engineering, malware research, and cyber threat intelligence.