CYFIRMA Research

CYFIRMA Research- Re-Emerging Telegram Phishing Campaign Targeting User Authorization Prompts

CYFIRMA

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 3:14

CYFIRMA has identified an active Telegram phishing campaign that abuses Telegram’s legitimate login and in-app authorization workflows to fully compromise user accounts without malware or exploits. By leveraging QR codes and manual login flows tied to attacker-controlled Telegram API credentials, victims are tricked into approving genuine authorization prompts inside the Telegram app under false security pretexts. This abuse-of-function approach increases victim trust, enables large-scale global targeting through rapidly rotating domains, and reflects a continued shift toward leveraging legitimate platform features as a primary account takeover vector.

Stay vigilant. Authentication prompts are only safe when you initiate the action.

Link to the Research Report: Re-Emerging Telegram Phishing Campaign Targeting User Authorization Prompts - CYFIRMA

#ThreatIntelligence #Telegram #Phishing #AccountTakeover #CyberSecurity  #SocialEngineering #CYFIRMA #CYFIRMAresearch #ETLM  #ExternalThreatLandscapeManagement

https://www.cyfirma.com/