Finance Phishing Lures Feed Telegram Data Leaks

AhnLab ASEC · Medium sophistication
Last updated July 30, 2026

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information was exfiltrated to attackers via the Telegram API, alongside dark-web sales of financial datasets and access credentials.

How the attack worked

This campaign relied on business-sounding email themes such as money transfer notices, receipts, and voicemail alerts to pressure recipients into clicking a link or opening an attachment. Those links and attachments led to login pages designed to harvest credentials. A second variant used attachment filenames crafted to resemble tax and payment receipts or HR and contract documents, aiming to build trust before the recipient opened the file. Phishing was the most common initial access method observed in the financial sector, frequently followed by downloaders or infostealers in multi-stage attack chains.

Why it succeeded

The lures worked because they mimicked routine business communication that finance, accounting, treasury, and HR staff handle daily. A message about a transfer receipt or a voicemail does not stand out as unusual in these workflows, which lowers scrutiny. Attachment filenames were deliberately structured to resemble real business documents, tax and payment receipts, and HR or contract paperwork, making them look legitimate at a glance. HTML attachments made up the largest share of malicious files, and script-based extensions such as js, vbe, vbs, bat, and hta were also common, both of which can bypass casual visual inspection since they don't look like traditional executable threats.

What to watch for

  • Unexpected emails referencing a money transfer, receipt, or voicemail that push you toward a link or attachment
  • HTML files presented as documents, especially when unsolicited
  • Attachment filenames that closely resemble tax, payment, HR, or contract paperwork but arrive outside normal document exchange processes
  • Login pages reached through an email link or attachment that don't match your organization's normal sign-in flow
  • Script-based file extensions like js, vbe, vbs, bat, or hta attached to business-themed emails

How to build resistance

Organizations in finance, insurance, fintech, banking, and asset management should treat money transfer, receipt, and voicemail-themed emails as high-risk until verified through a separate, trusted channel. Staff should be trained to view HTML attachments with the same caution as executables, since HTML accounted for the largest share of malicious attachments in this reporting period. Because stolen account information was reportedly exfiltrated to attackers through the Telegram API, rapid reporting of suspected phishing matters: the faster a suspicious email is flagged, the less time attackers have to move stolen credentials off-site. Techniques referenced in this campaign map to spearphishing via link (T1566.002), spearphishing attachment (T1566.001), and user execution of malicious files (T1204.001), which security awareness programs can use as a basis for targeted training scenarios.

Key findings

  • Phishing was the most prevalent initial access method for the financial sector in June, often followed by downloaders/droppers and then infostealers in multi-stage chains.
  • HTML attachments were the most common malicious attachment type, suggesting heavy use of HTML-based phishing pages and related techniques.
  • Korean-language attachment names were designed to look like real business documents (e.g., tax/payment receipts and HR/contract paperwork) to build trust.
  • Stolen account information gathered via malware infections and phishing emails was leaked to attackers via the Telegram API; phishing emails used themes like “money transfer,” “receipt,” and “voicemail.”
  • The report also highlights dark-web activity: alleged sales of leaked databases, ransomware/extortion victim claims, and sales of access credentials.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Treasury, HR, Procurement, Operations, Executive assistants.
  • Affected industries: Financial services, Insurance, Fintech, Banking, Asset management.
  • Attack channels: email, website.
  • Impersonated: A bank/payment service or internal finance system (masquerading as a legitimate login page), External business partner or internal HR/finance team (via a realistic-looking document filename).

Red flags to watch for

  • Unexpected message pressuring you to view a transfer/receipt/voicemail via a link or attachment
  • HTML attachment used as the ‘document’
  • Link/attachment leads to a login page that doesn’t match normal company sign-in flow
  • Attachment filename looks like a sensitive business document but arrives unexpectedly
  • Script-based attachment types (e.g., .js, .vbe) or web-document types (e.g., .html)
  • Sender context doesn’t match normal document exchange processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What phishing themes are being used against finance teams?

Attackers used routine business themes like money transfer notices, receipts, and voicemail alerts to get recipients to click links or open HTML attachments leading to fake login pages.

Why are HTML attachments a concern in this campaign?

HTML accounted for the largest share of malicious attachments, often paired with script-based extensions like js, vbe, vbs, bat, and hta, which are used to build convincing fake login pages.

What happens to stolen credentials in this campaign?

Stolen account information collected through malware infections and phishing emails was leaked to attackers through the Telegram API, allowing rapid off-site exfiltration.

Who is most targeted by these phishing lures?

Finance, accounting, treasury, HR, procurement, operations, and executive assistant roles are the primary targets, particularly within financial services, insurance, fintech, banking, and asset management.

Read the video transcript

You get an email: “Subject: Money transfer receipt, please review.” Looks routine, right? The email pushes you to click a link or open an HTML “receipt.” That opens a login page that looks like your bank or finance portal, but it’s fake. Here’s the nasty part: the moment you type your ID and password, that data can be shot straight out through the Telegram API and sold on dark‑web markets within minutes. If an email about money transfers, receipts, or voicemail asks you to log in from a link or HTML file, stop, report it as phishing and verify the request through our normal finance or HR channels.

Similar attacks

Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
Fake Resumes + Watering Holes Hit AnySign4PC Users

Fake Resumes + Watering Holes Hit AnySign4PC Users

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed. In some cases, simply visiting a compromised page triggered the exploit and installed SIGNBT or COPPERHEDGE backdoors without any download…

July 30, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026