logo

Smishing Alert: Telegram Bots Power New PNB MetLife Phishing Campaign

ID: 3f768243-195e-5410-8312-d701553ac649

STIX ID: report--3f768243-195e-5410-8312-d701553ac649

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

A widespread phishing campaign impersonating PNB MetLife uses SMS lures and mobile-optimized fake payment pages to steal personal and banking data and to coerce UPI payments; stolen data is exfiltrated in real time via hardcoded Telegram bots (e.g., pnbmetlifesbot, goldenxspy_bot) and operator accounts (darkdevil_pnb, prabhatspy), while clipboard manipulation and deep links prime victims to send funds. The attackers host and rapidly rotate pages on EdgeOne Pages, and a more dangerous variant captures full bank and card details for broader financial fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.