Summary
The core message of the provided session excerpt is that Hydra Saiga’s operations are valuable to study because their tooling is simple, observable, and operationally revealing: the group uses commodity techniques and Telegram-based command-and-control in ways that defenders can inspect once bot tokens are recovered. The speaker opens by clarifying that “Arrakis” is a thematic reference rather than a Dune cyber-operations talk, then introduces their background in threat intelligence, incident response, SOC work, and research into Telegram as C2 for both nation-state and e-crime actors. The case study begins with the September 2024 compromise of Karakil, a small Kyrgyz village about six hours from Bishkek, and asks why such a remote municipality would be targeted.
The speaker attributes the compromise to Hydra Saiga, also known as Eurotrooper by Cisco Talos, Shadowsilk by Group-IB, and Silent Links. Active since 2021, the group is described as targeting government, energy, and critical infrastructure in Central Asia, Europe, and the Middle East. Its toolkit includes commodity tools such as Chisel, Resox, Proxy, and Havoc, alongside custom backdoors written in languages including Golang, Rust, PowerShell, and Python. The infection chains shown are conventional but effective: phishing emails from compromised or spoofed government-related accounts, encrypted RAR archives, PDF decoys, malicious Word macros, PowerShell scripts, and, in another campaign, a malicious executable targeting Turkmenistan that runs a Base64-encoded PowerShell payload.
The central technical section explains how the Telegram Bot API enables two-way attacker control. The speaker walks through bot creation via Botfather, the structure of Telegram bot URLs, and key methods such as sendMessage and getUpdates. In the decoded backdoor logic, the malware sends victim data to a chat and polls for commands such as /sleep, /cmd, and /download. A live demonstration shows an infected victim responding to whoami, ipconfig, directory listing, file exfiltration of a “confidential.pdf,” file delivery through Telegram-generated URLs, and registry run-key persistence. The practical point is that an operator can control victims and exfiltrate files with minimal infrastructure.
The excerpt then pivots to defender collection and operational weaknesses. The speaker notes that the Telegram backdoor lacked user ID validation, meaning anyone who found the bot could potentially send commands to victims, remove persistence, or, in lucky cases, interfere with an operator’s own test environment. For defenders, the speaker compares Telegram’s forwardMessage method, which is noisy, single-chat, and blocked by protected content, with a stealthier Telethon-based get messages approach that impersonates a Telegram client as the bot. The speaker demonstrates their TeleScout tool, which exports bot metadata, chat summaries, JSON logs, HTML chat reconstructions, and selected files while avoiding automatic download of very large archives.
Key Topics
5 key topics from Pol Thill at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Extract bot tokens from malware to inspect operator communications.
- Monitor Telegram Bot API traffic in suspicious PowerShell execution chains.
- Check Telegram backdoors for missing user ID validation.
- Use stealthier collection methods to avoid tipping off operators.
- Avoid automatically downloading large archives during bot-log collection.
“you can literally just do it on your phone in the car if you if you wanted to do that.”

Pol Thill
Threat Researcher•TBD
Up Next

Next in agenda
How we accidentally built a nation-scale tracking system
Harrison Sand

Also on threat intelligence
VShell: Tracking a State-Actor C2 Framework in the Wild

Also on threat intelligence
The Evolution of Adversarial AI in Cyber Operations
Daniel Kapellmann Zafra