Telegram Phishing Campaign Targets Activists and Users in Russia, Belarus, and Kazakhstan
A sophisticated phishing campaign is using Telegram's encrypted chats to trick users, including exiled Belarusian activists, into revealing account credentials.

Researchers have uncovered a highly personalized phishing campaign that leveraged Telegram's end-to-end encrypted secret chat feature to target exiled Belarusian activists and users in Russia and Kazakhstan. The operation, documented by digital security organization Resident NGO, began with fake security alerts sent from unfamiliar accounts registered to Kazakhstani phone numbers. These messages falsely claimed victims had violated Telegram's rules and warned of account blocking unless they clicked a provided link to verify their account.
The attack was meticulously crafted, with each phishing link individualized to include the target's phone number, enabling attackers to track who opened the malicious URL. The primary goal was not to install malware, but to trick victims into divulging Telegram's one-time login code. If successfully obtained before its expiration, the attackers could immediately seize control of the victim's Telegram account.
Analysis revealed 64 distinct phone numbers, predominantly Russian, embedded within these personalized phishing links, suggesting a broad list of potential targets. However, the researchers emphasized that the presence of these numbers in links does not confirm that every link was delivered or that any accounts were ultimately compromised.
A key sophistication of the campaign lay in its infrastructure, which performed browser and device checks before presenting the phishing page. Intended targets were shown a fake Telegram login page, while security tools and many desktop users were redirected to Telegram's legitimate website or harmless pages, significantly hindering detection.
Attackers also appeared to monitor link engagement. Following a link's activation, a second message was sent, falsely claiming incomplete verification and warning of suspicious activity. This message included specific details about the victim's device, access time, and internet service provider, information likely gathered during the initial link click to lend credibility and pressure the user into completing the compromised login process.
To further evade automated detection, the threat actors employed obfuscation techniques, substituting visually similar Latin and Greek characters for some Cyrillic letters within their phishing messages. Despite these advanced tactics, Resident NGO could not ascertain the total number of individuals targeted or confirm if any accounts were successfully compromised, nor was the ultimate objective of the campaign or the intended use of compromised accounts determined.
The techniques observed align with account hijacking operations that have previously targeted Belarusian civil society, though those often involved deploying spyware. This campaign, however, demonstrates the effectiveness of social engineering alone, proving that a single, tailored message delivered privately can be sufficient to compromise an account without any malware deployment.