Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.
Two reports released last week by digital security organization Resident NGO document how the operation targeted at least one Belarusian activist living in Lithuania and appears to be part of a broader Telegram phishing campaign against users in Belarus, Russia, and Kazakhstan since at least October 2024.
The attack began with a fake Telegram security alert sent through the app’s end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the victim had violated Telegram’s rules and warned their account would be blocked unless they clicked a link to verify it.
One of the targeted users recognized the phishing attempt, did not enter any credentials, and reported the messages to Resident NGO for analysis.
Researchers said each phishing link was created for a specific person and included that person’s phone number, allowing the attackers to track who opened it. Instead of installing malware, the attackers tried to trick victims into entering Telegram’s one-time login code. If they entered the code before it expired, the attackers could immediately take control of the victim’s Telegram account.
Researchers said they found 64 distinct phone numbers, mostly Russian, embedded in individualized phishing links. “These numbers are likely intended targets, but the records alone cannot prove that every link was delivered or that any account was compromised,” they said.
The most advanced part of the campaign was not the fake login page itself but the infrastructure behind it, Resident NGO said. Before displaying the phishing page, the attackers checked the visitor’s browser and device. If the visitor matched the intended target, they were shown a fake Telegram login page. Security tools and many desktop users, however, were redirected to Telegram’s real website or other harmless pages, making the attack much harder to detect.
Researchers said the attackers also appeared to track who opened the phishing links. After a target visited the page, the operators sent a second message claiming the account verification was still incomplete and warning about suspicious activity.
The message included details about the person’s device, the time they opened the link, and their internet service provider — information collected when the link was opened. Researchers said this was likely intended to make the warning appear legitimate and pressure the victim into completing the login process.
To further evade automated detection, the attackers disguised parts of their phishing messages by replacing some Cyrillic letters with visually similar Latin and Greek characters.
Resident NGO said it could not determine how many people were targeted or whether any accounts were ultimately compromised. It is also unclear what the ultimate goal of the campaign was or how any compromised accounts would have been used.
Researchers said the techniques used in this campaign were consistent with account hijacking operations that have repeatedly targeted Belarusian civil society. Many of those attacks, however, relied on deploying sophisticated spyware on victims’ devices.
In 2024, digital rights organizations Access Now and Citizen Lab found that at least seven Russian- and Belarusian-speaking journalists and opposition activists living in Latvia, Lithuania, and Poland had been targeted with Pegasus spyware.
Last year, Reporters Without Borders disclosed a previously unknown spyware tool, dubbed ResidentBat, that was discovered on the phone of a Belarusian journalist who believed the malware had been installed while they were detained by Belarus’ KGB.
According to Resident NGO, the latest spying campaign shows that some of the most effective attacks against civil society require no malware at all.
“A single, carefully crafted message — delivered privately and tailored to a specific individual — can be sufficient to compromise an account,” researchers said.
Recorded Future
Intelligence Cloud.
