logo

PNB MetLife Phishing Attack: Multi-Stage Scheme Steals Data, Triggers UPI Payments

ID: 0eaea41a-9f9b-5f98-81eb-93666a31771b

STIX ID: report--0eaea41a-9f9b-5f98-81eb-93666a31771b

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** A multi-stage mobile-optimized phishing campaign is actively targeting PNB MetLife customers using fake payment gateway pages hosted on EdgeOne Pages and Telegram bots (@pnbmetlifesbot, @goldenxspy_bot) to exfiltrate policyholder data and banking credentials in real time; the attack forces UPI payments via QR codes and clipboard abuse and escalates to full credential harvesting, with operators using accounts such as @darkdevil_pnb and @prabhatspy — defenders should block malicious EdgeOne subdomains, monitor Telegram indicators, and educate customers to avoid SMS payment links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.