Join our Telegram channel @MilleniumRatcom for the latest Millenium RAT intelligence updates.

Research Library
analysis

How Millenium RAT Uses Telegram for Command and Control

Cyber Threat Intelligence Research Team·Published 2023-11-03·Updated 2026-10-04
Summary

Millenium RAT abuses the legitimate Telegram Bot API for command-and-control and data exfiltration. HTTPS to Telegram blends into normal cloud traffic, reducing the need for dedicated attacker infrastructure. Telegram is abused, not the malware's author.

Key Takeaways
  • ▸Telegram Bot API is the documented C2 channel.
  • ▸HTTPS to Telegram blends into normal cloud traffic.
  • ▸Reduces need for dedicated attacker-hosted C2.
  • ▸Telegram is a legitimate platform being abused.
  • ▸Blocking all Telegram is rarely the right policy answer.

Telegram is central to Millenium RAT's architecture. Public research documents the use of the Telegram Bot API for command-and-control communication and the transfer and exfiltration of stolen information.

At a defensive architectural level, the flow is: victim endpoint → Millenium RAT process → HTTPS communications → Telegram Bot API → attacker-controlled Telegram infrastructure. The compromised machine makes HTTPS requests to the Telegram Bot API; the attacker controls operation through a bot token and chat.

Criminals abuse legitimate cloud platforms like Telegram because little dedicated C2 infrastructure is required, HTTPS traffic blends into normal cloud traffic, Telegram provides globally accessible infrastructure, bot APIs simplify communication, and infrastructure resilience improves compared with a single attacker-hosted server.

It is critical to state clearly that Telegram itself is a legitimate messaging platform being abused by malware operators. Telegram did not create or support Millenium RAT. The abuse of a legitimate service is a property of the attacker's choice of infrastructure, not of the service.

For network detection, organizations should not simply block all Telegram traffic universally. Policy decisions should be based on business requirements. Instead, look for unexpected Telegram Bot API communication from processes that normally should not access Telegram, repeated HTTPS polling, and suspicious traffic involving known campaign infrastructure.

FAQ

Did Telegram create Millenium RAT?

No. Telegram is a legitimate platform being abused by the malware operators.

References

  1. [1]CYFIRMA, Unveiling a New Threat: The Millenium RAT, November 3, 2023
  2. [2]Group-IB, Millenium: A RAT Rewritten, A Threat Multiplied, June 25, 2026

Related Articles

Reviewed byCyber Threat Intelligence Research Team·Last verified: 2026-10-04
Millenium RAT Full Tech package — 0.10 BTC — contact for access