Researchers reported an aggressive phishing operation impersonating PNB MetLife Insurance to steal policyholder data and drive fraudulent payments, likely initiated via smishing lures that send victims to mobile-optimized “premium payment gateway” pages. The sites are designed to exploit brand trust and prompt users for personal details (e.g., name, policy number, mobile number) while performing no real backend validation—accepting arbitrary inputs and advancing users through the flow, indicating the pages are built for data capture rather than legitimate premium processing.
Technical analysis found the campaign avoids traditional attacker infrastructure by using the Telegram Bot API for near-real-time exfiltration of victim-submitted data. The malicious JavaScript reportedly contains hardcoded bot tokens/chat identifiers (including bots referenced as pnbmetlifesbot and goldenxspy_bot), and at least one observed lure domain was hosted on an EdgeOne subdomain (e.g., hxxps://pnb-metlife-g-shiv-1aad8zgyup.edgeone.app/). Victims are then redirected toward UPI payment steps, consistent with financial fraud objectives and a mobile-first targeting strategy.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers found the phishing kit was hosted on EdgeOne Pages, a free hosting platform, with multiple deployments showing minor configuration changes such as different UPI IDs, Telegram bots, and subdomains. This infrastructure choice enabled rapid rotation and resilience against takedowns while preserving the same malicious logic.
A more dangerous variant of the fake PNB MetLife pages was observed offering policy-service options such as refunds and auto-debit updates, then prompting victims for bank account and debit card information under a verification pretext. This showed the campaign had escalated from simple payment fraud to broader financial credential theft.
Researchers documented that one phishing template collected policy and identity details, then redirected victims into fraudulent UPI payment flows using generated QR codes, deep links to apps such as PhonePe and Paytm, and clipboard-copy abuse to prefill an attacker-controlled UPI ID. The campaign was described as mobile-optimized and likely distributed through smishing messages.
Multiple phishing pages impersonating PNB MetLife Insurance were identified as fake premium payment and policy-servicing portals that perform no legitimate payment processing or backend validation. The pages were found to steal victim-entered data by sending it to attackers through the Telegram Bot API using hardcoded bot tokens and chat IDs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.