[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)
2026-04-22T01:23:46Z•38dea43ae857a7bff0c9116bd659f00135894560373f803aadfc6d3b420f7c7d
ArechClient2CVE-managementDVREPSSIoT-compromiseLummaStealerSectopRATaudio-steganographycredential-harvestingcryptojackinghoneypotmalwaretdatatelegramthreat-intelwav
What happened
SANS ISC diary roundup (Apr 15–22, 2026) covering multiple incidents and research: a honeypot investigation showing Telegram 'tdata' files used as a credential-harvesting vector beyond cryptojacking; reports of malicious use of .wav files as malware delivery; a write-up on handling large CVE volumes using EPSS; an observed Lumma stealer infection paired with Sectop RAT (ArechClient2); and guest analysis of compromised DVRs in the wild. The posts include operational lessons from a honeypot, IoT/DVR compromise findings, and indicators of evolving delivery and credential theft techniques.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 38dea43ae857a7bff0c9116bd659f00135894560373f803aadfc6d3b420f7c7d
- Enrichment time
- 2026-04-22T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.