A phishing campaign built almost entirely inside Telegram itself, rather than over email or SMS, spent close to two years trying to hijack the account of an exiled Belarusian activist along with users across Russia and Kazakhstan, according to two reports from digital security organization Resident NGO detailed by The Record from Recorded Future News. The operation combined individually tailored messages with technical tricks built to dodge both spam filters and human suspicion, a reminder that account takeover increasingly runs on social engineering rather than malware.
What happened in the Telegram phishing campaign?
Resident NGO, a digital security group that says it has spent over a decade helping NGOs, journalists, human rights defenders and activists across Eastern Europe, found the campaign has been active since at least October 2024, according to The Record. Its most recent report traces roughly two years of activity aimed at users in Russia, Belarus and Kazakhstan, with at least one confirmed target: a Belarusian activist now living in exile in Lithuania.
The attack opened with a fake Telegram security alert sent through the app’s own end to end encrypted secret chat feature, from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the recipient had violated Telegram’s rules and warned the account would be blocked unless they clicked a link to verify it, a pretext built specifically to get the target to hand over a one time login code rather than to plant malware on the device.
| What happened | A Telegram based phishing campaign sent fake account violation alerts via encrypted secret chat to try to hijack accounts, according to Resident NGO and The Record. |
|---|---|
| When | Active since at least October 2024; latest Resident NGO report published in late July 2026. |
| Who is affected | An exiled Belarusian activist living in Lithuania, plus Telegram users across Russia, Belarus and Kazakhstan. |
| Scale | 64 distinct phone numbers, mostly Russian, found embedded in individualized phishing links; total number of victims unknown. |
| Goal | Capture one time login codes to hijack Telegram accounts directly; no malware was deployed. |
| Recommended action | Verify any account blocked alert inside Telegram’s own settings, never enter a login code received via an unsolicited link. |
Because the phishing flow targeted Telegram’s own login mechanism rather than a third party credential set, a successful hit would have handed attackers a working session inside the target’s actual account, secret chats and contact list included. That is a materially different risk than a reused password on some marketing site, and it echoes a pattern security teams have watched grow across messaging platforms generally, from OTP bot fraud services sold on criminal forums to state linked operations like the one Australia’s ASD flagged against a Russian zero click phishing campaign targeting Zimbra webmail.
How did the attackers make each message feel personal?
Researchers said the phishing links were individualized, each one embedding the target’s own phone number so operators could track who had clicked. Follow up messages layered on device details, login timestamps and ISP information to make the security alert look like it came from Telegram’s real systems rather than an outside party. Resident NGO summed up why that mattered in a line quoted by The Record: \”A single, carefully crafted message, delivered privately and tailored to a specific individual, can be sufficient to compromise an account.\”
Researchers said they identified 64 distinct phone numbers, most of them Russian, embedded across the individualized phishing links they recovered, though they cautioned that figure reflects what turned up in their sample rather than the full scope of the operation.
Why did the attackers swap Cyrillic letters for lookalike characters?
The campaign layered in evasion measures on both ends of the attack. Phishing pages reportedly ran browser and device checks before rendering, and traffic that looked like it came from a security researcher or automated scanner was quietly redirected to Telegram’s legitimate site or to a harmless page instead of the credential harvesting form. Within the messages themselves, operators replaced some Cyrillic characters with visually near identical Latin and Greek letters, a homoglyph trick aimed at slipping past keyword based spam and abuse filters that scan for exact match phrases.
None of this required deploying malware. The entire operation lived in convincing a target to type a code into a form, the same soft spot that has made one time password interception one of the more durable fraud techniques of the last several years, and one that keeps showing up whenever attackers can get a victim to treat a message as more official than it is.
What don’t researchers know yet?
Resident NGO was direct about the limits of its own findings, per The Record: it could not determine how many people were targeted in total, whether any accounts were actually compromised, what the campaign’s ultimate objective was, or how attackers intended to use any accounts they did take over. For a campaign running against activists, journalists and ordinary users across three countries for close to two years, that is a wide gap, and it leaves open whether this is intelligence gathering, account resale, or something else entirely.
What should security leaders take from this?
The specific targets here are civil society figures, not corporations, but the mechanics translate directly to any organization that leans on Telegram, WhatsApp or similar apps for internal or customer facing communication. An attacker who can spoof a platform’s own voice inside an encrypted channel, personalize the lure with real account details, and evade both filters and manual review, does not need a zero day to get in. That is squarely a training and process problem, not just a technical one, and it lines up with the broader shift toward CISOs needing to reason about human targeted deception as much as infrastructure hardening.
Practically, that means treating any unsolicited account blocked message, on any platform, as a prompt to verify independently through the app’s own settings rather than through a link in the message, and it means one time codes should never be entered anywhere except the login screen that generated them. Programs that frame this kind of vigilance as an individual failing tend to backfire, which is part of why rebuilding a security culture that treats reporting as normal rather than punished matters more than another policy memo. It also argues for shifting budget from one off phishing tests toward the kind of continuous, role specific awareness work outlined in the debate over security awareness training versus full human risk management programs, since a single well timed message, as Resident NGO put it, can be enough.
The credential theft angle also fits a broader trend security teams tracked through mid 2026, when incidents like the FortiBleed credential trove exposing tens of thousands of Fortinet logins showed how quickly stolen access, however it is obtained, gets aggregated and reused at scale. Whether an account is compromised through a leaked device credential or a well timed Telegram message, the downstream risk to an organization’s contacts, communications and reputation is the same, and it argues for verifying identity out of band before acting on any urgent account or security notice, no matter how convincing the message looks.
Frequently asked questions
What was the Telegram phishing campaign targeting Belarusian, Russian and Kazakhstani users?
It was a phishing operation that sent fake Telegram account suspension alerts through the app’s own encrypted secret chat feature, trying to trick recipients into handing over one time login codes. Resident NGO reported it had run since at least October 2024, targeting an exiled Belarusian activist and users in Russia and Kazakhstan.
How many people were affected by the campaign?
The exact number of victims is unknown. Resident NGO said it could not determine how many people were targeted in total or whether any accounts were actually compromised, though researchers identified 64 distinct phone numbers, mostly Russian, embedded in the individualized phishing links they recovered.
Why were Cyrillic characters replaced with Latin and Greek letters in the phishing messages?
Attackers swapped some Cyrillic letters for visually similar Latin and Greek characters to evade keyword based spam and abuse filters that scan messages for exact matching text. The phishing pages also screened visiting browsers and redirected suspected security researchers to Telegram’s legitimate site instead of the credential harvesting form.

Leave a Reply