How Millenium RAT Uses Telegram for Command and Control
Telegram is central to Millenium RAT's architecture. Here is how and why the legitimate platform is abused — and what that means for detection.
Does Millenium RAT use Telegram? Yes. Public research documents Millenium RAT using the Telegram Bot API for command-and-control communication and the transfer/exfiltration of stolen information. Telegram is a legitimate messaging platform being abused by the malware operators; Telegram did not create or support the malware.
The C2 architecture
At a defensive architectural level, Millenium RAT's command-and-control flow looks like this:
The compromised machine runs the Millenium RAT process, which makes HTTPS requests to the Telegram Bot API. The attacker controls the operation through attacker-controlled Telegram infrastructure (a bot token and chat). Commands flow down; exfiltrated data flows up — all over what looks like ordinary HTTPS to a well-known cloud service.
Why criminals abuse legitimate cloud platforms
- ▸ Little dedicated C2 infrastructure is required.
- ▸ HTTPS traffic blends into normal cloud traffic.
- ▸ Telegram provides globally accessible infrastructure.
- ▸ Bot APIs simplify communication.
- ▸ Infrastructure resilience improves compared with a single attacker-hosted server.
- 01Telegram Bot API is the documented C2 channel.
- 024.x uses libcurl to talk to the Telegram API.
- 03Traffic is HTTPS to a legitimate, well-known domain.
- 04Telegram is abused — not the author of the malware.
- 05Blocking all Telegram is rarely the right policy answer.
Important distinction: Telegram is a legitimate messaging platform being abused by malware operators. Telegram did not create or support Millenium RAT. Do not imply that Telegram created or endorses the malware.
Network detection — without blocking all Telegram
Do not simply block all Telegram traffic universally. Organizations should make policy decisions based on business requirements. Instead, look for:
- Unexpected Telegram Bot API communication from processes that normally should not access Telegram
- Repeated HTTPS polling behavior
- Suspicious traffic involving known campaign infrastructure
- Unexpected large data transfers
- Unusual cloud / file-hosting uploads
api.telegram.org/bot<token>/getUpdatesToken redacted. Pattern is documented in Group-IB research; the bot token is the attacker-controlled secret.
- ▸Millenium RAT abuses the Telegram Bot API for C2 and exfiltration.
- ▸HTTPS to Telegram blends into normal cloud traffic.
- ▸Telegram is a legitimate platform — not the malware's author.
- ▸4.x uses libcurl to communicate with the Telegram API.
- ▸Detect anomalous Telegram access by process, not by blocking all Telegram.

