rsload.net
Piracy / Warez portal
Malware confirmed
9.2/10

Piracy software portal positioning itself as a source of 'verified' cracks. Analysis of files downloaded from this resource revealed a professional multi-component trojan with ransomware capabilities disguised as a legitimate installer. Payload is packed inside Inno Setup and is invisible to antivirus software during static analysis (0 detections). If one file contains malware of this level, there is no reason to trust other distributions.

Threat type
Trojan + Ransomware
AV Detection
0 / N (FUD)
Persistence
3 independent mechanisms
Recommendation
Block at DNS level
Related reports
Critical VEGAS.rar — Trojanized Pirated Installer (MAGIX VEGAS Pro 23) 2026-03-23
telega.me
Spyware distribution / MITM proxy
Spyware confirmed
8.0/10

Official distribution website for Telega, an unofficial Telegram client (ru.dahl.messenger) with a built-in Man-in-the-Middle attack against the MTProto protocol. The application replaces Telegram DC IP addresses with proxy servers controlled by AS203502 ("JSC TELEGA", upstream: VK/Mail.ru), injects a rogue RSA key, disables Perfect Forward Secrecy, suppresses secret chats, and operates government censorship panels (Zeus/Cerberus) processing RKN blocking requests. Also distributed via Telegram channels @dahlmessenger and @telegaru.

Threat type
Spyware + MITM Proxy
Sandbox Score
8 / 10 (Likely Malicious)
Infrastructure
AS203502 (VK upstream)
Recommendation
Block at DNS level
Related reports
Critical Telega Messenger — MITM Attack on Telegram (ru.dahl.messenger) 2026-03-24