Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TWEAKOS Malware Exploits Telegram for Account Theft

TWEAKOS Malware Exploits Telegram for Account Theft

Posted on September 26, 2026 By CWS

TWEAKOS malware has emerged as a new threat by transforming Telegram into a platform for account theft and unauthorized access. This malware combines a Windows-based stealer with a Telegram bot, enabling operators to manage compromised accounts and sell access to them.

Unveiling the TWEAKOS Threat

The source code of TWEAKOS was initially discovered on Pastebin, leading researchers to identify two Python components linked to the malware. Despite this discovery, the method of distribution and the number of affected users remain unknown. The malware poses a risk to Discord accounts and can establish a reusable Telegram login session.

Flare’s analysis connected these components through shared bot credentials, revealing a sophisticated operation that not only steals accounts but also sets up a marketplace for selling them. A stolen Discord token provides unauthorized access, while a Telegram session allows impersonation of the account owner.

Operational Insights and Vulnerabilities

The TWEAKOS stealer is designed to persist on infected Windows systems by either copying itself to the Startup folder or creating a user-level startup entry. This persistence strategy does not require administrative privileges, making the malware resilient to system reboots.

Once active, the stealer searches for Discord authentication tokens stored locally and verifies them before sending valid tokens to the operators via Telegram. Unlike broader browser-stealing malware, TWEAKOS focuses on confirming the functionality of these tokens.

The Telegram Marketplace Connection

A second Python component operates the Telegram bot, maintaining a local database of victims, buyers, and transactions. The marketplace offers discounted Telegram and Discord accounts, with prices dropping daily. This direct connection between theft and commerce is a hallmark of TWEAKOS’s strategy.

Researchers noted discrepancies in the database records and the actual stolen data, suggesting that operators might receive account details without proper recordkeeping. Flare advises checking operator chat logs for a more accurate understanding of stolen data.

To mitigate risks, affected users should invalidate compromised Telegram sessions, revoke Discord tokens, and enable multi-factor authentication. Unusual requests for login codes or passwords should be treated with suspicion.

Indicators of compromise include the use of legitimate Telegram and Discord API endpoints for unauthorized activities, persistence files on Windows systems, and specific patterns in session file names.

For comprehensive threat intelligence integration, security teams are encouraged to leverage platforms like MISP or VirusTotal. This approach can significantly reduce investigation times and enhance response strategies.

Cyber Security News Tags:account theft, Botnet, Cybercrime, Cybersecurity, data protection, Discord, Flare analysis, Malware, multi-factor authentication, Python components, security threats, stolen accounts, Telegram, TWEAKOS, Windows stealer

Post navigation

Previous Post: Salmon Launches EVI to Secure AI and Autonomous Systems
Next Post: ServiceNow Urges Patching Critical Vulnerabilities

Related Posts

Langflow Vulnerability Exploited for AWS Key Theft Langflow Vulnerability Exploited for AWS Key Theft Cyber Security News
CVE-2026-39987 Exploited to Deploy Blockchain Backdoor CVE-2026-39987 Exploited to Deploy Blockchain Backdoor Cyber Security News
Outerlimit Secures M for AI Agent Security Innovation Outerlimit Secures $16M for AI Agent Security Innovation Cyber Security News
Top 10 Best Cyber Threat Intelligence Companies in 2025 Top 10 Best Cyber Threat Intelligence Companies in 2025 Cyber Security News
1inch partners with Innerworks to strengthen DeFi security through AI-Powered threat detection 1inch partners with Innerworks to strengthen DeFi security through AI-Powered threat detection Cyber Security News
OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ServiceNow Urges Patching Critical Vulnerabilities
  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ServiceNow Urges Patching Critical Vulnerabilities
  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark