What Is Gaslight Malware 2026 and Why It Defeats AI-Powered SIEMs
Gaslight Malware 2026 refers to Rust-compiled implants that use Telegram as their command-and-control (C2) channel. Beyond evading antivirus detection, they actively inject false events into your logs to train your AI SIEM to normalize malicious activity as benign. At Blurtek we have identified this pattern in security audits of Spanish SMEs that believed their active security solutions were providing adequate protection.
The implants do not connect to suspicious IPs — they poll api.telegram.org over standard HTTPS, identical to what Telegram Desktop does on any corporate workstation. Your perimeter firewall, TLS inspection proxy, and SIEM all see legitimate traffic to a trusted destination. According to the CCN-CERT 2025 Threat Report, use of legitimate messaging apps as C2 channels grew 156% year-over-year across documented European incidents. No IP reputation alert fires because there is nothing to flag.
Suspect your AI SIEM may be operating on contaminated data or have unexplained traffic to api.telegram.org? Contact Blurtek for an incident response audit.
Solicitar diagnóstico