Threat Intelligence, Phishing, Application security

Phishing campaigns now target Telegram infrastructure

A close-up view of the Telegram messaging app is seen on a smart phone on May 25, 2017 in London, England. SafeGuard Cyber Division Seven (D7) threat intelligence team located and confirmed an instance where a company’s employees had been targeted in a previously-known cryptocurrency impersonation scheme as far back as July 2022. (Photo by Ca...

Cybersecurity researchers have observed a growing trend of threat actors exploiting Telegram's Bot API to covertly exfiltrate sensitive data from high-value organizations and government entities, reports Cyber Security News.

The attacks combine traditional phishing with legitimate messaging platforms, using fake login pages to harvest credentials that are then transmitted directly to attacker-controlled Telegram bots. Analysts highlight the sophistication of these campaigns, noting JavaScript-based credential interception embedded in authentic-looking HTML interfaces that mirror trusted portals. Cybersecurity enthusiast cocomelonc identified domain-specific phishing pages in Kazakhstans public sector that pre-fill targeted email addresses to enhance credibility. Beyond credential theft, these intrusions facilitate lateral movement within networks, enabling prolonged access and data collection. Researchers stress that using Telegram as a communication channel allows attackers to bypass conventional security controls, as data flows through encrypted, legitimate infrastructure. They advise organizations to adopt comprehensive monitoring, including JavaScript behavior analysis and network traffic inspection, to detect and mitigate these stealthy exfiltration techniques before attackers gain persistent access.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds