logo

New Telegram Phishing Scam Hijacks Login Flow to Steal Fully Authorized User Sessions

ID: 30f01e5a-89a4-5307-9830-c6cc92f38f03

STIX ID: report--30f01e5a-89a4-5307-9830-c6cc92f38f03

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-09

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

A sophisticated global phishing campaign abuses Telegram's legitimate authentication features (API credentials, QR-code login, and OTP/manual login) to trick users into authorizing attacker-controlled sessions. The attackers relay login attempts to Telegram's official APIs and use social engineering to convince victims to approve in-app prompts, enabling full account takeover and further spread by messaging victims' contacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.