logo

Telegram Phishing Campaign Hijacks Accounts by Abusing Trust

ID: 40f2d935-d16e-53a7-8001-9104dc4fa8c6

STIX ID: report--40f2d935-d16e-53a7-8001-9104dc4fa8c6

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-13

Date Updated: 2026-04-23

Author: Ddos

...
...

CYFIRMA reports a large-scale phishing campaign that abuses Telegram's legitimate authorization prompts to perform account takeovers: victims visiting spoofed sites are coached to scan QR codes or enter phone numbers, which trigger real in-app authorization requests on their devices. The attackers use a configuration-driven, multilingual framework that supports rapid domain rotation and mass deployment, enabling persistent, high-volume operations that bypass traditional credential-harvesting defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.