Suspicious Termination of Telegram Desktop Prior to Session Theft

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a taskkill command forcibly terminating the Telegram desktop client. The Arkanix stealer kills Telegram.exe before copying its tdata session folder so the locked files can be stolen and used for account takeover as reported by Kaspersky. Forced termination of Telegram by a non-interactive process is a strong precursor to messaging session credential theft.

Related detections9 linkedT1555.003 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Windows SQLite CLI Querying Chromium Browser Profile Databases
Suspicious Download of Edge Login Data Stealer via curl
Suspicious Chrome Masquerade Running from ProgramData Google Path (via process_creation)
Suspicious Browser Remote Debugging Port Cookie Theft via process_creation
Malicious Credential Stealer PowerShell Script Names Targeting Financial Services
Suspicious ipconfig Reconnaissance Output Redirected to CentreStack Log File
Malicious VietCredCare Credential Exfiltration Staging Files
Suspicious Termination of Telegram Desktop Prior to Session Theft
Pivot detection · T1555.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.