Telegram is central to Millenium RAT's architecture. Public research documents the use of the Telegram Bot API for command-and-control communication and the transfer and exfiltration of stolen information.
At a defensive architectural level, the flow is: victim endpoint → Millenium RAT process → HTTPS communications → Telegram Bot API → attacker-controlled Telegram infrastructure. The compromised machine makes HTTPS requests to the Telegram Bot API; the attacker controls operation through a bot token and chat.
Criminals abuse legitimate cloud platforms like Telegram because little dedicated C2 infrastructure is required, HTTPS traffic blends into normal cloud traffic, Telegram provides globally accessible infrastructure, bot APIs simplify communication, and infrastructure resilience improves compared with a single attacker-hosted server.
It is critical to state clearly that Telegram itself is a legitimate messaging platform being abused by malware operators. Telegram did not create or support Millenium RAT. The abuse of a legitimate service is a property of the attacker's choice of infrastructure, not of the service.
For network detection, organizations should not simply block all Telegram traffic universally. Policy decisions should be based on business requirements. Instead, look for unexpected Telegram Bot API communication from processes that normally should not access Telegram, repeated HTTPS polling, and suspicious traffic involving known campaign infrastructure.

