Phishing Campaign Targets Exiled Belarusian Activist and Users in Russia and Kazakhstan
Researchers at Resident NGO have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan. The attack began with a fake Telegram security alert sent through the app's end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number.
The message falsely claimed the victim had violated Telegram's rules and warned their account would be blocked unless they clicked a link to verify it. One of the targeted users recognized the phishing attempt, did not enter any credentials, and reported the messages to Resident NGO for analysis.
Personalized Phishing Links
Researchers said each phishing link was created for a specific person and included that person's phone number, allowing the attackers to track who opened it. Instead of installing malware, the attackers tried to trick victims into entering Telegram's one-time login code. If they entered the code before it expired, the attackers could immediately take control of the victim's Telegram account.
Researchers said they found 64 distinct phone numbers, mostly Russian, embedded in individualized phishing links. These numbers are likely intended targets, but the records alone cannot prove that every link was delivered or that any account was compromised.
Advanced Infrastructure
The most advanced part of the campaign was not the fake login page itself but the infrastructure behind it, Resident NGO said. Before displaying the phishing page, the attackers checked the visitor's browser and device. If the visitor matched the intended target, they were shown a fake Telegram login page. Security tools and many desktop users, however, were redirected to Telegram's real website or other harmless pages, making the attack much harder to detect.
Researchers said the attackers also appeared to track who opened the phishing links. After a target visited the page, the operators sent a second message claiming the account verification was still incomplete and warning about suspicious activity. The message included details about the person's device, the time they opened the link, and their internet service provider — information collected when the link was opened.
Evasion Techniques
To further evade automated detection, the attackers disguised parts of their phishing messages by replacing some Cyrillic letters with visually similar Latin and Greek characters. Resident NGO said it could not determine how many people were targeted or whether any accounts were ultimately compromised.
The techniques used in this campaign were consistent with account hijacking operations that have repeatedly targeted Belarusian civil society. Many of those attacks, however, relied on deploying sophisticated spyware on victims' devices. In 2024, digital rights organizations Access Now and Citizen Lab found that at least seven Russian- and Belarusian-speaking journalists and opposition activists living in Latvia, Lithuania, and Poland had been targeted with Pegasus spyware.
A single, carefully crafted message — delivered privately and tailored to a specific individual — can be sufficient to compromise an account.
According to Resident NGO, the latest spying campaign shows that some of the most effective attacks against civil society require no malware at all. The organization's researchers said that the campaign highlights the importance of being cautious when receiving unexpected messages, even if they appear to be from a legitimate source.
Source: The Record