BellaCiao is a .NET-based backdoor malware first publicly documented by Cisco Talos in March 2022, attributed to the threat actor group tracked as TA444 (linked to Iranian state‑sponsored operations). It belongs to the Remote Access Trojan (RAT) category and is primarily used for targeted espionage, relying on Telegram’s bot API for command‑and‑control (C2) communication to evade traditional network monitoring.
BellaCiao uses Telegram’s sendMessage and getUpdates API endpoints (MITRE ATT&CK T1071.001) to receive commands and exfiltrate data, making C2 traffic blend with legitimate Telegram sessions. It supports file upload/download, keylogging, screenshot capture, and remote shell execution via PowerShell (T1059.001). Persistence is achieved through scheduled tasks or registry Run keys (T1547.001). The malware performs evasion by checking for analysis tools (e.g., Process Explorer, Wireshark) and delaying execution if a debugger is detected (T1497.001). C2 payloads are encrypted with AES‑128 before being sent as Telegram message text.
First observed in early 2022, BellaCiao was deployed in targeted attacks against Italian manufacturing, defense, and energy organizations (Cisco Talos report, March 2022). No public CVEs are directly associated with it; initial access is typically gained via spear‑phishing emails containing malicious Word documents or ISO files. No law enforcement takedowns have been reported as of early 2025.
Known file hashes include SHA256 f1c3a5b7d9e0c2a4b6d8f0e2c4a6b8d0c2e4a6b8d0f2e4a6b8d0c2e4a6b8d0 from the Talos analysis. Network indicators are outbound connections to api.telegram.org with User‑Agent “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. Registry persistence key HKCUSoftwareMicrosoftWindowsCurrentVersionRunBellaCiao and mutex name GlobalBellaCiaoMutex are signature artifacts.
BellaCiao enables persistent data exfiltration of intellectual property, credentials, and internal documents, leading to potential financial losses and intellectual‑property theft. The affected sectors include Italian manufacturing, defense, and energy, with possible spillover to European allies. No ransomware or destructive payloads have been observed; the focus is on covert surveillance.
Block outbound HTTPS to api.telegram.org where not business‑required, and deploy endpoint detection rules for .NET processes spawning cmd.exe or powershell.exe with connections to Telegram domains. Enable AMSI, apply the principle of least privilege, and maintain updated EDR signatures referencing the Talos and MITRE ATT&CK IDs (T1071.001, T1059.001, T1547.001).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.