Telegram: TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace

Telegram: TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace

TWEAKOS Malware Hijacks Messaging Accounts for Sale via Telegram Storefront

Researchers at Flare have uncovered TWEAKOS, a malware operation that steals Discord and Telegram accounts, turning them into sellable commodities through an integrated Telegram bot storefront. The threat emerged after its source code appeared on Pastebin, though the initial infection vector and victim count remain unknown.

How the Malware Works

The attack leverages a Windows stealer paired with a Telegram bot for managing victims and facilitating sales. Key capabilities include:

  • Discord Token Theft: The malware scans local storage for Discord authentication tokens (including test builds and Chrome’s default profile), validates them via Discord’s API, and exfiltrates working credentials to operators.
  • Telegram Session Hijacking: The stealer prompts victims for their phone number and login code, then uses Telethon to generate a new session file. If successful, it sends the session to two operator-controlled accounts, granting unauthorized access without resetting the victim’s password.
  • Persistence: The malware ensures longevity by copying itself into the Startup folder or adding a user-level registry entry, allowing it to relaunch after system reboots without requiring admin privileges.

The Telegram Storefront

A second Python component powers a Telegram bot-based marketplace, where stolen accounts are listed for sale. Features include:

  • Dynamic Pricing: Accounts are discounted by 5% per day, up to a 70% reduction, with a minimum price of one Telegram Star (the platform’s virtual currency).
  • Automated Sales: Buyers receive credentials after payment, while operators maintain a local database tracking victims, products, and orders.
  • Coercive Tactics: Operators can trigger a script that displays a repeating warning message on victims’ screens, referencing a fake security update (though the payload remains unverified).

Operational Flaws & Detection

Flare’s analysis revealed inconsistencies in the malware’s design:

  • Database Gaps: Stolen accounts are sent directly to operator chats, but the bot’s database may miss compromised accounts due to capitalization mismatches in Discord token checks.
  • Invalid Invites: A Discord invite link (discord[.]gg/tweakos) embedded in the coercive message was found to be non-functional during testing.

Indicators of Compromise (IoCs)

Security teams should monitor for:

  • Persistence Mechanisms: Unusual entries in the Startup folder (SystemHelper.exe) or registry (HKCU\Software\Microsoft\Windows\CurrentVersion\Run).
  • Token Validation Traffic: Requests to discord[.]com/api/v9/users/@me following access to Discord’s local storage.
  • Telegram Session Files: Files matching patterns like {phone}.session or session_{uid}.session appearing alongside outbound Telegram traffic.
  • Database & Scripts: The bot’s SQLite database (tweakos_data.db) and per-victim scripts (blocker_{uid}.vbs).

While the malware’s delivery method remains unconfirmed, its focus on validated tokens and session-based access rather than password resets distinguishes it from broader browser-stealing threats. Defenders are advised to prioritize operator chat records over the bot’s database for accurate victim tracking.

Source: https://cybersecuritynews.com/tweakos-malware/

Telegram TPRM report: https://www.rankiteo.com/company/telegram-messenger

"id": "tel1790346347",
"linkid": "telegram-messenger",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'Individual users'}],
 'attack_vector': 'Unknown (source code leaked on Pastebin)',
 'data_breach': {'data_exfiltration': 'Yes (credentials and session files sent '
                                      'to operator-controlled accounts)',
                 'file_types_exposed': ['Discord tokens',
                                        'Telegram session files',
                                        'SQLite database (tweakos_data.db)'],
                 'personally_identifiable_information': 'Potential (account '
                                                        'details, phone '
                                                        'numbers, messages)',
                 'sensitivity_of_data': 'High (account access, personally '
                                        'identifiable information via '
                                        'messaging platforms)',
                 'type_of_data_compromised': 'Authentication tokens, session '
                                             'files, account credentials'},
 'description': 'Researchers at Flare uncovered TWEAKOS, a malware operation '
                'that steals Discord and Telegram accounts, turning them into '
                'sellable commodities through an integrated Telegram bot '
                'storefront. The threat emerged after its source code appeared '
                'on Pastebin, though the initial infection vector and victim '
                'count remain unknown.',
 'impact': {'data_compromised': 'Discord and Telegram account credentials, '
                                'session tokens',
            'identity_theft_risk': 'High (account hijacking, session theft)',
            'operational_impact': 'Unauthorized access to messaging accounts, '
                                  'potential misuse of compromised accounts',
            'systems_affected': 'Windows systems with Discord/Telegram '
                                'installed'},
 'initial_access_broker': {'backdoors_established': 'Persistence via Startup '
                                                    'folder or registry',
                           'data_sold_on_dark_web': 'Yes (via Telegram bot '
                                                    'storefront)',
                           'high_value_targets': 'Discord and Telegram '
                                                 'accounts'},
 'investigation_status': 'Ongoing (initial analysis by Flare)',
 'lessons_learned': 'Defenders should prioritize monitoring for operator chat '
                    'records over bot databases for accurate victim tracking. '
                    "The malware's focus on validated tokens and session-based "
                    'access distinguishes it from broader browser-stealing '
                    'threats.',
 'motivation': 'Financial gain (selling stolen accounts)',
 'post_incident_analysis': {'corrective_actions': ['Enhanced monitoring for '
                                                   'token/session theft',
                                                   'User education on malware '
                                                   'risks',
                                                   'Improved detection of '
                                                   'persistence mechanisms'],
                            'root_causes': 'Leaked source code on Pastebin, '
                                           'exploitation of Discord/Telegram '
                                           'local storage and session '
                                           'management'},
 'recommendations': ['Monitor for unusual persistence mechanisms (Startup '
                     'folder, registry entries).',
                     'Track Discord token validation traffic to '
                     'discord[.]com/api/v9/users/@me.',
                     'Detect Telegram session files and outbound Telegram '
                     'traffic patterns.',
                     'Prioritize operator chat records for victim tracking due '
                     'to database inconsistencies.'],
 'references': [{'source': 'Flare'}],
 'response': {'enhanced_monitoring': ['Monitor for persistence mechanisms '
                                      '(Startup folder, registry entries)',
                                      'Monitor for Discord token validation '
                                      'traffic '
                                      '(discord[.]com/api/v9/users/@me)',
                                      'Monitor for Telegram session files and '
                                      'outbound Telegram traffic'],
              'third_party_assistance': 'Flare (research and analysis)'},
 'threat_actor': 'Unknown (TWEAKOS operators)',
 'title': 'TWEAKOS Malware Hijacks Messaging Accounts for Sale via Telegram '
          'Storefront',
 'type': 'Malware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.