{"id":56006,"date":"2026-06-23T13:27:33","date_gmt":"2026-06-23T17:27:33","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56006"},"modified":"2026-06-23T13:27:33","modified_gmt":"2026-06-23T17:27:33","slug":"telegram-no-password-session-stealer","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/telegram-no-password-session-stealer\/56006\/","title":{"rendered":"Your Telegram account can be stolen without a password or verification code"},"content":{"rendered":"<p>There are dozens of ways to break into someone else\u2019s Telegram account. We\u2019ve frequently covered <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-mini-app-phishing\/55041\/\" target=\"_blank\" rel=\"noopener nofollow\">phishing in Telegram Mini Apps<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/54090\/\" target=\"_blank\" rel=\"noopener nofollow\">scams with bots, gifts, and giveaways<\/a>, and many other tactics. Today, we\u2019re looking at yet another account hijacking method, one that relies on a PowerShell script.<\/p>\n<p>The script, deceptively named \u201cWindows Telemetry Update\u201d, actually serves as a tool for hijacking Telegram sessions. It harvests data from <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">completely defenseless<\/a>\u00a0user computers and forwards it to the attackers via a Telegram bot.<\/p>\n<h2>An evil script with a stealer inside<\/h2>\n<p>Cybercriminals frequently rely on PowerShell scripts to covertly download malware or harvest data. This time, researchers <a href=\"https:\/\/flare.io\/learn\/resources\/blog\/telegram-session-stealerpastebin-hosted-powershell-script-targets-desktop-web-sessions\" target=\"_blank\" rel=\"noopener nofollow\">uncovered<\/a> a script on Pastebin masquerading as a routine Windows update. In reality, it was an infostealer designed to hijack Telegram for Windows session data and allow hackers to take over accounts without a password or verification code.<\/p>\n<blockquote><p>What\u2019s a PowerShell script anyway? Think of it as a text file packed with commands for a Windows computer. Instead of a human spending time clicking through tasks manually, the computer follows these quick instructions to get everything done automatically in a matter of seconds.<\/p><\/blockquote>\n<div id=\"attachment_56010\" style=\"width: 1411px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/06\/23132626\/telegram-no-password-session-stealer-01.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56010\" class=\"wp-image-56010 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/06\/23132626\/telegram-no-password-session-stealer-01.png\" alt=\"This PowerShell script steals Telegram for Windows session data, letting hackers hijack accounts without a password or verification codes\" width=\"1401\" height=\"874\"><\/a><p id=\"caption-attachment-56010\" class=\"wp-caption-text\">This PowerShell script steals Telegram for Windows session data, letting hackers hijack accounts without a password or verification codes<\/p><\/div>\n<p>Right at the top of the script, researchers immediately spotted a Telegram bot token and a chat ID, alongside multiple references to the <em>tdata<\/em> folder. This specific folder is where Telegram for Windows keeps the authorization keys used to log users in to its servers. If attackers grab this data, they can access the victim\u2019s Telegram account without a password or verification code. Once inside, they maintain access until the victim checks their active sessions in the app and manually terminates the suspicious ones.<\/p>\n<h2>How the stealer works<\/h2>\n<p>The malware lands on the victim\u2019s computer disguised as a PowerShell script for a Windows telemetry update. As soon as it runs, it gathers basic system information: the username, hostname, and public IP address. It then checks if Telegram Desktop is installed. If it is, the script forces the app to close so it can unlock Telegram files for editing.<\/p>\n<p>From there, the rest is simple: the script zips up the entire contents of the <em>tdata<\/em> folder into a temporary directory, forwards the archive straight to the attackers, and wipes the file from the computer to erase its tracks.<\/p>\n<p>The good news is that the stealer likely hasn\u2019t compromised any accounts yet, as experts found no evidence of actual data transfers. It appears researchers caught this malicious PowerShell script while it was still in the prototype testing phase.<\/p>\n<p>Another giveaway is its surprisingly suspicious name. Cybercriminals typically use neutral names to hide their bots and apps. In this case, when researchers found it, the bot was running under the burner handle <em>afhbhfsdvfh_bot<\/em> with a dead-honest description: <em>Telegram attacker<\/em>. Researchers noted that while the bot had likely undergone functional testing, it hadn\u2019t yet been deployed at scale, which explains the placeholder name.<\/p>\n<h2>How to defend against PowerShell scripts<\/h2>\n<p>Defending against this nameless stealer requires a layered approach to security. First, it helps to understand how a PowerShell script ends up on your PC in the first place. Usually, they slip in unnoticed through malicious email attachments, software vulnerabilities, infected apps, or social engineering tricks. That\u2019s why we recommend installing a\u00a0<a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">robust security suite<\/a> on your device and staying highly cautious about the links you click and the files you download.<\/p>\n<ul>\n<li><strong>Be careful what you download.<\/strong> Always double-check the websites you use to download files. Stick to trusted, official sources\u00a0\u2014 and remember that Telegram and <a href=\"https:\/\/www.kaspersky.com\/blog\/hijacked-discord-invite-links-for-multi-stage-malware-delivery\/53955\/\" target=\"_blank\" rel=\"noopener nofollow\">Discord channels<\/a>, and sketchy, fly-by-night websites definitely don\u2019t fit that description.<\/li>\n<li><strong>Watch out for email links and attachments. <\/strong>Keep in mind that email remains a favorite delivery method for cybercriminals. They might drop a PowerShell script directly into your inbox as an attachment or bait you into clicking a link that triggers an automatic download.<\/li>\n<li><strong>Keep your apps and OS updated. <\/strong>Software vulnerabilities pop up unexpectedly, but patches are usually released very quickly. We recommend installing updates as soon as they become available. To make life easier, just turn on automatic updates wherever possible.<\/li>\n<\/ul>\n<p>Make sure to install <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Premium<\/a>\u00a0on every device where you run Telegram. Our security solution will block malware, malicious attachments, spam, phishing attempts, and sketchy websites. <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Premium<\/a> subscription additionally includes a <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener nofollow\">password manager<\/a>. It\u2019ll generate and securely store strong and unique passwords, stop you from entering your credentials on fake sites, and come in handy for tightening your Telegram security, which we\u2019ll cover next.<\/p>\n<h2>How to secure your Telegram account<\/h2>\n<p>To protect your Telegram account from these types of hijacking schemes, make sure to:<\/p>\n<ul>\n<li><strong>Regularly monitor your Telegram activity.<\/strong> Ultimately, hackers steal accounts to blast out spam and run scams. It\u2019s a good idea to periodically check your chat history to ensure no new conversations or messages have appeared that you didn\u2019t send yourself.<\/li>\n<li><strong>Immediately terminate unrecognized sessions.<\/strong> If you suspect you\u2019ve fallen victim to this infostealer or any other cyberattack, terminate all other Telegram sessions as soon as possible by going to <em>Settings<\/em> \u2192 <em>Devices<\/em> \u2192 <em>Terminate all other sessions<\/em>.<\/li>\n<\/ul>\n<p>If your Telegram account has already been hijacked, you have a strict 24-hour window to kick the attackers out by terminating their sessions. We broke down exactly why this rule exists\u00a0\u2014 and mapped out every possible way to reclaim your account\u00a0\u2014 in our detailed guide: <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-account-hacked\/52775\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>What to do if your Telegram account is hacked<\/strong><\/a><strong>.<\/strong><\/p>\n<p>In the meantime, beefing up your account security is a must. First, set up a cloud password by heading to <em>Settings<\/em> \u2192 <em>Privacy and Security<\/em> \u2192 <em>Two-Step Verification<\/em>. Just any password won\u2019t cut it\u00a0\u2014 you need something unique and unhackable. We recommend reading our post on the subject: <a href=\"https:\/\/www.kaspersky.com\/blog\/international-password-day-2025\/53355\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Creating an unforgettable password<\/strong><\/a>.<\/p>\n<p>Better yet, make the switch to <a href=\"https:\/\/www.kaspersky.com\/blog\/full-guide-to-passkeys-in-2025-part-1\/53688\/\" target=\"_blank\" rel=\"noopener nofollow\">passkeys<\/a>\u00a0\u2014 a passwordless technology that offers top-tier protection against leaks and phishing. To set up that login method, go to <em>Settings<\/em> \u2192 <em>Privacy and Security<\/em> \u2192 <em>Passkeys<\/em>. The easiest way to manage your passkeys is with <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Password Manager<\/a>. Our cross-platform app ensures you can seamlessly log in to Telegram using your saved passkeys whether you are on Windows, Android, iOS, or macOS.<\/p>\n<blockquote><p>To learn more about how cybercriminals can breach your Telegram account and how to lock it down, check out our other posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-mini-app-phishing\/55041\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Phishing in Telegram Mini Apps: what\u2019s Habib\u2019s papakha got to do with it?<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/54090\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Telegram scams with bots, gifts, and crypto<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-prevent-whatsapp-telegram-account-hijacking-and-quishing\/53012\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>WhatsApp and Telegram account hijacking: <\/strong><\/a><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-prevent-whatsapp-telegram-account-hijacking-and-quishing\/53012\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How to protect yourself against scams<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-premium-scam\/52696\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>You\u2019ve been sent a \u201cgift\u201d\u00a0\u2014 a Telegram Premium subscription<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-account-hacked\/52775\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>What to do if your Telegram account is hacked<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Hackers have developed a PowerShell script that hijacks Telegram sessions, granting an attacker access to accounts without a password or verification codes. Here&#8217;s a breakdown of how it works and how to stay safe.<\/p>\n","protected":false},"author":2754,"featured_media":56007,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1788,2683],"tags":[2672,607,97,3244,611,422],"class_list":{"0":"post-56006","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-threats","9":"tag-accounts","10":"tag-messengers","11":"tag-security-2","12":"tag-stealers","13":"tag-telegram","14":"tag-threats"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/telegram-no-password-session-stealer\/56006\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/telegram-no-password-session-stealer\/30842\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/telegram-no-password-session-stealer\/25881\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/telegram-no-password-session-stealer\/30683\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/telegram-no-password-session-stealer\/42109\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/telegram-no-password-session-stealer\/30790\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/telegram-no-password-session-stealer\/36351\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/telegram-no-password-session-stealer\/36241\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/telegram\/","name":"telegram"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2754"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56006"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56006\/revisions"}],"predecessor-version":[{"id":56011,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56006\/revisions\/56011"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56007"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56006"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}