ToxicEye is a remote access trojan (RAT) first documented in June 2020 by researchers at Check Point Software Technologies. It is operated by a threat actor tracked as TA869 (or "Cobalt Spider" association unconfirmed) and is distributed via phishing emails containing malicious Excel attachments that execute PowerShell downloaders. The malware uses Telegram’s API for command-and-control (C2), making it distinct from traditional RATs that rely on custom servers or IRC channels.
ToxicEye propagates primarily through spear-phishing campaigns with weaponized Microsoft Office lure documents (commonly using DDE or macro execution). Once executed, it installs a persistent backdoor by creating scheduled tasks and registry Run keys. The C2 infrastructure is unique: it uses Telegram bots to receive commands and exfiltrate data, sending telemetry over HTTPS to Telegram’s servers. Evasion techniques include obfuscated PowerShell payloads, process hollowing, and disabling Windows Defender through registry modifications. It can capture keystrokes, take screenshots, transfer files, execute shell commands, and download additional payloads such as ransomware or crypto miners. Persistence is achieved via a VBS script that relaunches the main executable on system startup. MITRE ATT&CK techniques observed include T1059.001 (PowerShell), T1047 (WMI), T1547.001 (Registry Run Keys / Startup Folder), and T1071.001 (Web Protocols).
ToxicEye first surfaced in June 2020 and was linked to a campaign targeting Israeli organizations, particularly in the education and technology sectors. Check Point’s June 2020 report identified over 100 Telegram bot tokens used for C2, indicating a wide operational scope. No specific CVEs have been directly tied to ToxicEye itself, as it leverages social engineering rather than exploiting software vulnerabilities. No major law enforcement actions have been reported against its operators as of early 2025. The malware’s reliance on Telegram for C2 has prompted Telegram to shut down hundreds of associated bot accounts upon discovery.
Network IOCs include outbound HTTPS connections to api.telegram.org with bot tokens in the URI path (e.g., `/bot
ToxicEye poses a severe threat to data confidentiality and system integrity, as it enables full remote control of infected machines. Impact includes credential theft, data exfiltration of sensitive documents, and deployment of secondary malware such as ransomware (e.g., STOP/DJVU variants have been observed following ToxicEye infections). The affected sectors primarily include education, technology, and small-to-medium businesses in Israel and the Middle East, though campaigns have targeted global victims. Financial losses are difficult to quantify but include business disruption, remediation costs, and data recovery expenses.
Defenders should block outbound connections to api.telegram.org unless explicitly required, deploy email filtering to detect malicious Excel attachments with DDE or macro content, and enable AMSI (Anti-Malware Scan Interface) for PowerShell. Detection rules are available in Check Point’s threat advisory (June 2020) and can be implemented via YARA signatures for the PowerShell downloader and Telegram API patterns. Regular patching of Office applications and user awareness training against spear-phishing are essential preventive measures. EDR solutions with behavioral detection can identify scheduled task creation and process hollowing attempts.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.