Phishing Kits and Campaigns: How Threat Actors are Exploiting Telegram

In recent months, cybersecurity researchers have discovered an alarming trend of threat actors using the popular messaging platform Telegram to peddle phishing kits and set up phishing campaigns. This new methodology of exploiting messaging apps is a worrying development and a reminder that cybercriminals are not just relying on traditional email phishing attacks to steal personal data.

Statistics

According to the Russian cybersecurity firm Kaspersky, over the past six months, it has detected more than 2.5 million malicious URLs generated using phishing kits. This number is incredibly high and highlights a significant increase in the number of phishing campaigns being conducted using Telegram.

Telegram bots

One of the most popular services offered by threat actors is the use of Telegram bots, which automate the process of generating phishing pages and collecting user data. These bots are sold on the dark web, and cybercriminals can buy them easily for a surprisingly low cost.

Personal data sharing

In some cases, phishers have even been observed sharing the personal data of users with other subscribers for free, in hopes of attracting aspiring criminals. This information can be used to carry out further attacks, making it an incredibly high-risk situation for individuals.

Paid services

Some of the more advanced phishing kits include features such as anti-bot detection, URL encryption, and geoblocking, making them even harder to detect. These kits are sold for anywhere between $10 and $280, highlighting the vast sums of money cybercriminals can make by conducting these types of attacks.

Sale of Personal Data

Another profitable business for cybercriminals is the sale of personal data, particularly bank account credentials. These details are advertised at different rates based on the balance of the account, highlighting the ruthless nature of these criminals.

Phishing-as-a-Service

Phishing services are now commonly marketed via Telegram on a subscription basis, known as phishing-as-a-service (PhaaS). Developers offer a monthly fee to rent the kits in return for providing regular updates, making it an incredibly cost-effective way of carrying out cyberattacks.

Low barrier to entry

“The threshold for joining the phisher community lowered once malicious actors migrated to Telegram and started sharing insights and knowledge, often for free, right there in the popular messaging service,” says Olga Svistunova, Kaspersky web content analyst. The ease with which these criminals can share information and their experiences with each other makes Telegram a breeding ground for these types of attacks.

Phishing attacks remain a significant problem in the cybersecurity world, and the use of messaging apps like Telegram only makes it easier for criminals to deploy their tactics. Individuals and organizations alike must be vigilant in protecting their personal information and adopt proper cybersecurity measures to prevent themselves from falling prey to these attacks. As we move forward, it is likely that we will see more creative and sophisticated approaches used by threat actors, highlighting the importance of staying up to date with the latest trends in cybersecurity.

Explore more

Microsoft Dynamics 365 Finance Transforms Retail Operations

In today’s hyper-competitive retail landscape, success hinges on more than just offering standout products or unbeatable prices—it requires flawless operational efficiency and razor-sharp financial oversight to keep pace with ever-shifting consumer demands. Retailers face mounting pressures, from managing multi-channel sales to navigating complex supply chains, all while ensuring profitability remains intact. Enter Microsoft Dynamics 365 Finance (D365 Finance), a cloud-based

How Does Microsoft Dynamics 365 AI Transform Business Systems?

In an era where businesses are grappling with unprecedented volumes of data and the urgent need for real-time decision-making, the integration of Artificial Intelligence (AI) into enterprise systems has become a game-changer. Consider a multinational corporation struggling to predict inventory shortages before they disrupt operations, or a customer service team overwhelmed by repetitive inquiries that slow down their workflow. These

Will AI Replace HR? Exploring Threats and Opportunities

Setting the Stage for AI’s Role in Human Resources The rapid integration of artificial intelligence (AI) into business operations has sparked a critical debate within the human resources (HR) sector: Is AI poised to overhaul the traditional HR landscape, or will it serve as a powerful ally in enhancing workforce management? With over 1 million job cuts reported in a

Trend Analysis: AI in Human Capital Management

Introduction to AI in Human Capital Management A staggering 70% of HR leaders report that artificial intelligence has already transformed their approach to workforce management, according to recent industry surveys, marking a pivotal shift in Human Capital Management (HCM). This rapid integration of AI moves HR from a traditionally administrative function to a strategic cornerstone in today’s fast-paced business environment.

How Can Smart Factories Secure Billions of IoT Devices?

In the rapidly evolving landscape of Industry 4.0, smart factories stand as a testament to the power of interconnected systems, where machines, data, and human expertise converge to redefine manufacturing efficiency. However, with this remarkable integration comes a staggering statistic: the number of IoT devices, a cornerstone of these factories, is projected to grow from 19.8 billion in 2025 to