Telegram’s Bot API is now a common covert channel for threat actors, from phishing kit operators to state-linked activity. Its structural appeal is clear: a simple HTTPS interface, strong domain reputation, and no attacker-controlled infrastructure required. Many implementations embed recoverable bot tokens and chat identifiers in HTML, JavaScript, or binary payloads.
...