Millenium RAT Campaign Infects Over 60,000 Devices via Telegram C2 (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Rewritten in native C++ to evade detection
- Uses Telegram Bot API for command and control
- Attributed to Y2K Operators; 62,289 infections recorded
"Group-IB reports that the Millenium RAT, now rewritten in C++, has infected 62,289 devices across more than 160 countries. The remote access trojan is sold as malware-as-a-service for as little as $50 for the first month and uses the Telegram Bot API for command and control. The threat actor tracked as Y2K Operators distributes the malware through social engineering lures such as game cheats and cracked software."
no comments yet.