← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Telegram Phishing Campaign Targets Belarusian Activist, Russian, and Kazakhstani Users

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Phishing campaign used Telegram secret chats for fake security alerts.
  • Targeted an exiled Belarusian activist and users in Russia and Kazakhstan.
  • Each phishing link was personalized with the target's phone number.
  • Attackers sought one-time login codes, not malware installation.

Targeted Phishing Operation

Digital security organization Resident NGO has documented a sophisticated Telegram phishing campaign. This operation specifically targeted an exiled Belarusian activist residing in Lithuania, alongside a broader set of users in Russia and Kazakhstan. The campaign has been active since at least October 2024.

Attack Methodology

The attack began with a fake Telegram security alert sent via the app's end-to-end encrypted secret chat feature. The message, originating from an unfamiliar account registered to a Kazakhstani phone number, falsely claimed the victim had violated Telegram's rules and threatened account blockage unless a verification link was clicked. One targeted user recognized the attempt and reported it to Resident NGO.

Personalized Links and Account Takeover

Researchers found that each phishing link was uniquely crafted for a specific individual, embedding their phone number to track interactions. Instead of deploying malware, the attackers aimed to trick victims into entering Telegram's one-time login code. If entered before expiration, this code would grant attackers immediate control over the victim's Telegram account. Resident NGO identified 64 distinct phone numbers, predominantly Russian, embedded in these individualized links.

Advanced Evasion Techniques

A notable aspect of the campaign was its sophisticated infrastructure. Before displaying the phishing page, the attackers checked the visitor's browser and device. Only if the visitor matched the intended target was the fake Telegram login page shown. Security tools and many desktop users were redirected to Telegram's legitimate website or other harmless pages, making the attack significantly harder to detect by general security measures.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A highly personalized Telegram phishing campaign has been uncovered, targeting an exiled Belarusian activist and users in Russia and Kazakhstan. The attackers used fake security alerts and custom phishing links to trick victims into revealing one-time login codes, aiming to hijack their Telegram accounts.