Specification of health data transfer from devices to DiGA (§ 374a SGB V)
: Unusual outgoing traffic to Telegram API endpoints ( api.telegram.org ) or Discord webhooks, which are commonly used as Command & Control (C2) channels.
: Saved passwords, cookies, and autofill credit card info from Chrome, Edge, and Firefox.
: Scans for browser extensions and local wallet files (e.g., MetaMask, Exodus).
: Usually distributed via phishing emails, cracked software sites, or "modding" forums targeting gamers.
: New, hidden folders in %AppData% containing .txt or .json files ready for upload. Recommended Actions
: Session tokens for Discord, Steam, and Minecraft.
: Change passwords for your email, banking, and primary social accounts from a different, clean device .