logo

Telegram Tango: Dancing with a Scammer

ID: b336b96c-29a8-53d9-a5fc-b435f76fbc7d

STIX ID: report--b336b96c-29a8-53d9-a5fc-b435f76fbc7d

Feed Name: Infoblox Threat Intel Blog

Threat Score
35/100

Date Published: 2025-05-06

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

A threat researcher engaged with a Telegram-based crypto "work-from-home" scam that used lookalike domains and social engineering to coerce victims into depositing cryptocurrency; the blog recounts training tasks, repeated demands for Ethereum deposits, attempts to spoof transaction evidence, a small successful payout, and eventual cutoff by the scammers. The report identifies multiple related domains likely using the same scam kit and highlights operational details (use of stock photos, mixed human/automated chat, wallet-based deposits) useful for detection and consumer warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.