Join our Telegram channel @MilleniumRatcom for the latest Millenium RAT intelligence updates.

Telegram C2

How Millenium RAT Uses Telegram for Command and Control

Telegram is central to Millenium RAT's architecture. Here is how and why the legitimate platform is abused — and what that means for detection.

Answer

Does Millenium RAT use Telegram? Yes. Public research documents Millenium RAT using the Telegram Bot API for command-and-control communication and the transfer/exfiltration of stolen information. Telegram is a legitimate messaging platform being abused by the malware operators; Telegram did not create or support the malware.

The C2 architecture

At a defensive architectural level, Millenium RAT's command-and-control flow looks like this:

01
Victim endpoint
↓
02
Millenium RAT process
↓
03
HTTPS communications
↓
04
Telegram Bot API
↓
05
Attacker-controlled Telegram infra

The compromised machine runs the Millenium RAT process, which makes HTTPS requests to the Telegram Bot API. The attacker controls the operation through attacker-controlled Telegram infrastructure (a bot token and chat). Commands flow down; exfiltrated data flows up — all over what looks like ordinary HTTPS to a well-known cloud service.

Why criminals abuse legitimate cloud platforms

  • ▸ Little dedicated C2 infrastructure is required.
  • ▸ HTTPS traffic blends into normal cloud traffic.
  • ▸ Telegram provides globally accessible infrastructure.
  • ▸ Bot APIs simplify communication.
  • ▸ Infrastructure resilience improves compared with a single attacker-hosted server.
Key Facts
  • 01Telegram Bot API is the documented C2 channel.
  • 024.x uses libcurl to talk to the Telegram API.
  • 03Traffic is HTTPS to a legitimate, well-known domain.
  • 04Telegram is abused — not the author of the malware.
  • 05Blocking all Telegram is rarely the right policy answer.

Important distinction: Telegram is a legitimate messaging platform being abused by malware operators. Telegram did not create or support Millenium RAT. Do not imply that Telegram created or endorses the malware.

Network detection — without blocking all Telegram

Do not simply block all Telegram traffic universally. Organizations should make policy decisions based on business requirements. Instead, look for:

  • Unexpected Telegram Bot API communication from processes that normally should not access Telegram
  • Repeated HTTPS polling behavior
  • Suspicious traffic involving known campaign infrastructure
  • Unexpected large data transfers
  • Unusual cloud / file-hosting uploads
Illustrative network pattern
api.telegram.org/bot<token>/getUpdates

Token redacted. Pattern is documented in Group-IB research; the bot token is the attacker-controlled secret.

Key Takeaways
  • ▸Millenium RAT abuses the Telegram Bot API for C2 and exfiltration.
  • ▸HTTPS to Telegram blends into normal cloud traffic.
  • ▸Telegram is a legitimate platform — not the malware's author.
  • ▸4.x uses libcurl to communicate with the Telegram API.
  • ▸Detect anomalous Telegram access by process, not by blocking all Telegram.
Reviewed byCyber Threat Intelligence Research Team·Last verified: 2026-10-04
Millenium RAT Full Tech package — 0.10 BTC — contact for access