logo

After two years, Telegram smishing is back, and account takeovers are here to stay

ID: 9ccda822-cc7c-54b6-8467-ac83cec259cc

STIX ID: report--9ccda822-cc7c-54b6-8467-ac83cec259cc

Feed Name: ASEC

Threat Score
55/100

Date Published: 2026-05-19

Date Updated: 2026-05-20

Author: ATCP

...
...

This report describes a renewed Telegram login smishing campaign in which phishing pages mimic Telegram, collect victims' phone numbers and login codes, and use user-agent bypass logic to avoid detection; compromised accounts can lead to leaked chats, personal data exposure, and secondary scams against contacts. It warns users not to follow unknown links, to avoid entering verification codes on external pages, and to enable two-step verification and session monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.