Researchers uncovered a highly tailored Telegram phishing operation that targeted at least one exiled Belarusian activist in Lithuania as well as users in Belarus, Russia, and Kazakhstan. The campaign used fake Telegram security alerts delivered through secret chats and individualized phishing links that embedded victims’ phone numbers, then presented a counterfeit login page designed to steal Telegram one-time passcodes. By capturing valid OTPs instead of deploying malware, the operators could immediately hijack accounts if victims entered the code before it expired.
The infrastructure showed signs of sustained regional activity, with RESIDENT.NGO linking the operation to broader OTP-phishing campaigns tracked for roughly two years across Russia, Belarus, and Kazakhstan. Investigators said the phishing links used device-aware filtering to display the fake login page only to intended targets while redirecting others to benign content, and also collected metadata including device details, timing, and ISP information from visits. That intelligence was reportedly used in follow-up messages to increase credibility and pressure targets, underscoring a persistent focus on account takeover against Belarusian civil society and other regional Telegram users.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The Record reported that the same phishing operation also targeted additional users in Belarus, Russia, and Kazakhstan. The report said researchers could not confirm how many people were targeted or whether any Telegram accounts were ultimately compromised.
Researchers documented a highly personalized Telegram phishing operation targeting at least one exiled Belarusian activist in Lithuania, with activity ongoing since at least October 2024. The attackers used fake Telegram security alerts in secret chats and individualized phishing links containing victims' phone numbers.
RESIDENT.NGO published an analysis of the Telegram phishing operation targeting an exiled Belarusian activist. The write-up detailed tactics including device-aware filtering and collection of device, timing, and ISP data to support follow-up social engineering.
RESIDENT.NGO reported a regional Telegram one-time-passcode phishing infrastructure targeting users in Russia, Belarus, and Kazakhstan for two years. The campaign used Telegram-focused phishing to steal login codes for account takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourceresident.ngo
Open sourceresident.ngo
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.