Telegram Phishing Campaign Hijacks Accounts by Abusing Trust
ID: 40f2d935-d16e-53a7-8001-9104dc4fa8c6
STIX ID: report--40f2d935-d16e-53a7-8001-9104dc4fa8c6
Feed Name: securityonline.info
CYFIRMA reports a large-scale phishing campaign that abuses Telegram's legitimate authorization prompts to perform account takeovers: victims visiting spoofed sites are coached to scan QR codes or enter phone numbers, which trigger real in-app authorization requests on their devices. The attackers use a configuration-driven, multilingual framework that supports rapid domain rotation and mass deployment, enabling persistent, high-volume operations that bypass traditional credential-harvesting defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
