BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Jul 27, 2026 · 3 min read · Original story

Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis

Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis

Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.

Two reports released last week by digital security organization Resident NGO document how the operation targeted at least one Belarusian activist living in Lithuania and appears to be part of a broader Telegram phishing campaign against users in Belarus, Russia, and Kazakhstan since at least October 2024.

The attack began with a fake Telegram security alert sent through the app's end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the victim had violated Telegram's rules and warned their account would be blocked unless they clicked a link to verify it.

One of the targeted users recognized the phishing attempt, did not enter any credentials, and reported the messages to Resident NGO for analysis.

Researchers said each phishing link was created for a specific person and included that person's phone number, allowing the attackers to track who opened it. Instead of installing malware, the attackers tried to trick victims into entering Telegram's one-time login code. If they entered the code before it expired, the attackers could immediately take control of the victim's Telegram account.

Researchers said they found 64 distinct phone numbers, mostly Russian, embedded in individualized phishing links. “These numbers are likely intended targets, but the records alone cannot prove that every link was delivered or that any account was compromised,” they said.

The most advanced part of the campaign was not the fake login page itself but the infrastructure behind it, Resident NGO said. Before displaying the phishing page, the attackers checked the visitor's browser and device. If the visitor matched the intended target, they were shown a fake Telegram login page. Security tools and many desktop users, however, were redirected to Telegram's real website or other harmless pages, making the attack much harder to detect.

Researchers said the attackers also appeared to track who opened the phishing links. After a target visited the page, the operators sent a second message claiming the account verification was still incomplete and warning about suspicious activity.

The message included details about the person's device, the time they opened the link, and their internet service provider — information collected when the link was opened. Researchers said this was likely intended to make the warning appear legitimate and pressure the victim into completing the login process.

To further evade automated detection, the attackers disguised parts of their phishing messages by replacing some Cyrillic letters with visually similar Latin and Greek characters.

Resident NGO said it could not determine how many people were targeted or whether any accounts were ultimately compromised. It is also unclear what the ultimate goal of the campaign was or how any compromised accounts would have been used.

Researchers said the techniques used in this campaign were consistent with account hijacking operations that have repeatedly targeted Belarusian civil society. Many of those attacks, however, relied on deploying sophisticated spyware on victims' devices.

In 2024, digital rights organizations Access Now and Citizen Lab found that at least seven Russian- and Belarusian-speaking journalists and opposition activists living in Latvia, Lithuania, and Poland had been targeted with Pegasus spyware.

Last year, Reporters Without Borders disclosed a previously unknown spyware tool, dubbed ResidentBat, that was discovered on the phone of a Belarusian journalist who believed the malware had been installed while they were detained by Belarus' KGB.

According to Resident NGO, the latest spying campaign shows that some of the most effective attacks against civil society require no malware at all.

“A single, carefully crafted message — delivered privately and tailored to a specific individual — can be sufficient to compromise an account,” researchers said.

References in this story

  1. Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist - RESIDENT.NGO THREAT LAB resident.ngo In July 2026, RESIDENT.NGO investigated a cloaked phishing operation targeting the Telegram account of an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram…
  2. A Telegram of Trouble: Tracking a regional OTP-phishing infrastructure targeting users in Russia, Belarus and… resident.ngo In July 2026, RESIDENT.NGO investigated a Telegram phishing message sent to a Belarusian activist living in Lithuania. The link led to a fake Telegram page that asked for a login code. The link also contained the target
  3. Exiled Russian, Belarusian opposition journalists targeted with Pegasus spyware therecord.media All of the newly identified Pegasus victims live in Europe in exile and had previously “faced intense threats” from Russia or Belarus, according to Access Now and Citizen Lab.
  4. New spyware discovered on Belarusian journalist’s phone after interrogation therecord.media Researchers at the nonprofit Reporters Without Borders discovered a previously unknown spyware tool on the phone of a Belarusian journalist who had been detained by security services.
  5. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
  6. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

Guides related to this story

← Back to all news