PNB MetLife Phishing Attack: Multi-Stage Scheme Steals Data, Triggers UPI Payments
ID: 0eaea41a-9f9b-5f98-81eb-93666a31771b
STIX ID: report--0eaea41a-9f9b-5f98-81eb-93666a31771b
Feed Name: GBHackers
**Executive summary:** A multi-stage mobile-optimized phishing campaign is actively targeting PNB MetLife customers using fake payment gateway pages hosted on EdgeOne Pages and Telegram bots (@pnbmetlifesbot, @goldenxspy_bot) to exfiltrate policyholder data and banking credentials in real time; the attack forces UPI payments via QR codes and clipboard abuse and escalates to full credential harvesting, with operators using accounts such as @darkdevil_pnb and @prabhatspy — defenders should block malicious EdgeOne subdomains, monitor Telegram indicators, and educate customers to avoid SMS payment links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
