← Back to feed
Threat Actors & CampaignsEmerging1 sourceJun 24, 2026 · 18:53via Constella Intelligence

Hunter Update: Telegram Intelligence, Infostealer Analysis, Threat Actor Identification

Brief

Hunter has added additional capabilities across three areas: live Telegram channel monitoring integrated directly into the investigation workflow, richer infostealer package analysis including browser history and session cookies, and a new threat actor identification engine that surfaces criminal profiles from fresh infostealer data.

Investigations move at the speed of the adversary. The channels, tools, and tactics that threat actors use to communicate, share stolen data, and coordinate attacks have shifted significantly toward Telegram, and the infostealer packages circulating in those channels now contain far more actionable intelligence than raw credential lists. Constella Hunter has been updated to reflect that reality.

These updates are live in production. Here is what is new, what it enables, and how to use it in investigations.

Read more on Constella Intelligence