Hackers used Telegram phishing campaign to target exiled Belarusian activist
Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal Telegram accounts, bypassing traditional security measures. Researchers found a sophisticated infrastructure that adapts to the user's device and browser to increase the likelihood of success, mirroring previous account hijacking operations against Belarusian civil society, some of which involved advanced spyware.
Researchers have uncovered a highly personalized phishing campaign targeting an exiled Belarusian activist, as well as users in Russia and Kazakhstan, utilizing Telegram to attempt to hijack their accounts. The operation began with a fake Telegram security alert sent through the app's end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the victim had violated Telegram's rules and warned their account would be blocked unless they clicked a link to verify it.
One of the targeted users recognized the phishing attempt, did not enter any credentials, and reported the messages to Resident NGO for analysis. Researchers found 64 distinct phone numbers, mostly Russian, embedded in individualized phishing links. These numbers were likely intended targets, but the records alone cannot prove that every link was delivered or that any account was compromised.
The most advanced part of the campaign was not the fake login page itself, but the infrastructure behind it. Before displaying the phishing page, the attackers checked the visitor's browser and device. If the visitor matched the intended target, they were shown a fake Telegram login page. Security tools and many desktop users, however, were redirected to Telegram's real website or other harmless pages, making the attack much harder to detect.
Researchers said the attackers also appeared to track who opened the phishing links. After a target visited the page, the operators sent a second message claiming the account verification was still incomplete and warning about suspicious activity. The message included details about the person's device, the time they opened the link, and their internet service provider — information collected when the link was opened. Researchers said this was likely intended to make the warning appear legitimate and pressure the victim into completing the login process.
To further evade automated detection, the attackers disguised parts of their phishing messages by replacing some Cyrillic letters with visually similar Latin and Greek characters. Researchers said the techniques used in this campaign were consistent with account hijacking operations that have repeatedly targeted Belarusian civil society. Many of those attacks, however, relied on deploying sophisticated spyware on victims’ devices.
In 2024, digital rights organizations Access Now and Citizen Lab found that at least seven Russian- and Belarusian-speaking journalists and opposition activists living in Latvia, Lithuania, and Poland had been targeted with Pegasus spyware. Last year, Reporters Without Borders disclosed a previously unknown spyware tool, dubbed ResidentBat, that was discovered on the phone of a Belarusian journalist who believed the malware had been installed while they were detained by Belarus’ KGB. According to Resident NGO, the latest spying campaign shows that some of the most effective attacks against civil society require no malware at all. “A single, carefully crafted message — delivered privately and tailored to a specific individual — can be sufficient to compromise an account,” researchers said.
Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
