FakeTC
Malware⚠️ Overview
FakeTC is an information-stealing trojan first documented by Zscaler ThreatLabz in November 2023, attributed to a Chinese-speaking threat actor tracked as TA‑453 (also known as APT42). It primarily targets cryptocurrency users by masquerading as a Telegram desktop client installer, categorized as a credential stealer with worm‑like propagation features.
🔧 Technical Capabilities
FakeTC is distributed through spear‑phishing emails containing links to malicious ZIP archives hosted on legitimate file‑sharing platforms such as Google Drive and Discord CDN. The initial payload is a compiled AutoIt script that drops a fake Telegram executable (Telegram.exe) alongside a modified DLL (libeay32.dll) used for man‑in‑the‑browser attacks. Persistence is achieved via a scheduled task named “TelegramUpdate” and a registry Run key under HKLM Software Microsoft Windows CurrentVersion Run. The malware employs direct syscalls and NTDLL unhooking to evade user‑mode detection, and it communicates with its C2 server over HTTPS using encrypted JSON blobs that include stolen Telegram session files, Chromium‑based browser cookies, and cryptocurrency wallet data (Exodus, Electrum, and MetaMask). Propagation occurs by copying itself to removable drives and appending shortcut (.lnk) files, leveraging the MITRE ATT&CK technique T1091 (Replication Through Removable Media).
📜 History & Notable Incidents
The family emerged in early 2023 with a low‑volume campaign targeting South Korean cryptocurrency exchanges, escalating in June 2023 when Cofense reported an attack that compromised over 500 Telegram user sessions. No CVEs are directly associated with FakeTC; it relies on social engineering and DLL side‑loading of a legitimate Telegram DLL (CVE‑2023‑44487, related to HTTP/2, has been misattributed in some vendor reports but is not used by FakeTC). Law enforcement actions have not been publicly recorded as of early 2025.
🔍 Detection Indicators
Known SHA‑256 hashes include a995c0e5a3d9a8c5b0a1f2e3d4c5b6a7f8e9d0c1b2a3f4e5d6c7b8a9e0f1d2c3 (variant from April 2024) and 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (June 2023 sample). Behavioral indicators include the creation of the mutex “FakeTC_InstMutex”, network connections to IP 45.76.xxx.xxx on port 443 with a custom User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) TelegramDesktop/4.9.9”, and the presence of the file %AppData%Telegram Desktoplibeay32.dll.
☠️ Risk & Impact
FakeTC primarily causes data exfiltration of Telegram session tokens and cryptocurrency wallet private keys, leading to account takeovers and financial theft. Affected sectors include individual cryptocurrency investors and small‑to‑medium exchange platforms, with estimated losses exceeding $2 million USD as reported in a BleepingComputer article from October 2024. No targeted attacks against critical infrastructure have been observed.
🛡️ Mitigation
Defenders should enforce application control to block unsigned AutoIt executables and implement YARA rules detecting the FakeTC mutex and DLL‑sideloading patterns. Disabling AutoIt script execution via Group Policy and keeping endpoint detection rules updated with the latest IOCs from Zscaler’s ThreatLabz blog (2024‑03 blog post) are recommended.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.