Sophisticated Telegram Phishing Targets Activists and Users in Eastern Europe
A highly personalized phishing campaign, leveraging **Telegram**'s secret chat feature, has been uncovered targeting an exiled Belarusian activist and users across Russia and Kazakhstan. This operation employs advanced social engineering and infrastructure to hijack accounts without deploying malware, highlighting a growing threat to civil society.
Digital security organization **Resident NGO** has exposed a sophisticated phishing campaign that has been active since at least October 2024. The operation primarily targets users in Belarus, Russia, and Kazakhstan, with a particular focus on civil society members.
### The Attack Vector: Personalized Phishing
The campaign begins with a fake security alert sent via **Telegram**'s end-to-end encrypted secret chat. These messages originate from unfamiliar accounts, often registered with Kazakhstani phone numbers, and falsely claim a violation of **Telegram**'s rules, threatening account blockage unless a verification link is clicked.
One targeted Belarusian activist, living in Lithuania, recognized the phishing attempt and reported it to **Resident NGO** for analysis, preventing a potential compromise.
### Individualized Links and OTP Hijacking
Researchers discovered that each phishing link was uniquely crafted for a specific individual, embedding their phone number. This technique allows attackers to track who opens the links and personalize subsequent interactions. Instead of deploying malware, the primary goal is to trick victims into entering their **Telegram** one-time login code (OTP). If entered before expiration, attackers can immediately seize control of the account.
**Resident NGO** identified 64 distinct phone numbers embedded in these individualized links, predominantly Russian. While these numbers likely represent intended targets, it's not confirmed how many links were delivered or if any accounts were successfully compromised.
### Evasive Infrastructure and Social Engineering
The campaign's most advanced aspect lies in its infrastructure. Before displaying the phishing page, attackers meticulously check the visitor's browser and device. Only if the visitor matches the intended target is the fake **Telegram** login page presented. Security tools and many desktop users are instead redirected to **Telegram**'s legitimate website or other benign pages, making the attack significantly harder to detect and analyze.
Attackers also track link openings. After a target visits the page, a second message is sent, falsely claiming incomplete account verification and warning of suspicious activity. This message includes details about the victim's device, the time of the link click, and their internet service provider β information collected during the initial visit. This tactic is designed to lend legitimacy to the warning and pressure the victim into completing the login process.
To further evade automated detection, the attackers subtly disguise parts of their phishing messages by replacing certain Cyrillic letters with visually similar Latin and Greek characters.
### Broader Context: Targeting Belarusian Civil Society
While **Resident NGO** could not determine the total number of individuals targeted or compromised, the techniques align with previous account hijacking operations against Belarusian civil society. Many past attacks, however, relied on sophisticated spyware deployments.
For example, in 2024, **Access Now** and **Citizen Lab** reported that at least seven Russian- and Belarusian-speaking journalists and opposition activists in Latvia, Lithuania, and Poland were targeted with **Pegasus** spyware. Last year, **Reporters Without Borders** disclosed **ResidentBat**, a previously unknown spyware tool found on the phone of a Belarusian journalist.
This latest campaign by **Resident NGO** underscores a critical shift: some of the most effective attacks against civil society now require no malware at all. As researchers note, βA single, carefully crafted message β delivered privately and tailored to a specific individual β can be sufficient to compromise an account.β
