Finance Phishing Lures Feed Telegram Data Leaks

AhnLab ASEC · Medium sophistication
Last updated July 30, 2026

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information was exfiltrated to attackers via the Telegram API, alongside dark-web sales of financial datasets and access credentials.

How the attack worked

This campaign relied on business-sounding email themes such as money transfer notices, receipts, and voicemail alerts to pressure recipients into clicking a link or opening an attachment. Those links and attachments led to login pages designed to harvest credentials. A second variant used attachment filenames crafted to resemble tax and payment receipts or HR and contract documents, aiming to build trust before the recipient opened the file. Phishing was the most common initial access method observed in the financial sector, frequently followed by downloaders or infostealers in multi-stage attack chains.

Why it succeeded

The lures worked because they mimicked routine business communication that finance, accounting, treasury, and HR staff handle daily. A message about a transfer receipt or a voicemail does not stand out as unusual in these workflows, which lowers scrutiny. Attachment filenames were deliberately structured to resemble real business documents, tax and payment receipts, and HR or contract paperwork, making them look legitimate at a glance. HTML attachments made up the largest share of malicious files, and script-based extensions such as js, vbe, vbs, bat, and hta were also common, both of which can bypass casual visual inspection since they don't look like traditional executable threats.

What to watch for

  • Unexpected emails referencing a money transfer, receipt, or voicemail that push you toward a link or attachment
  • HTML files presented as documents, especially when unsolicited
  • Attachment filenames that closely resemble tax, payment, HR, or contract paperwork but arrive outside normal document exchange processes
  • Login pages reached through an email link or attachment that don't match your organization's normal sign-in flow
  • Script-based file extensions like js, vbe, vbs, bat, or hta attached to business-themed emails

How to build resistance

Organizations in finance, insurance, fintech, banking, and asset management should treat money transfer, receipt, and voicemail-themed emails as high-risk until verified through a separate, trusted channel. Staff should be trained to view HTML attachments with the same caution as executables, since HTML accounted for the largest share of malicious attachments in this reporting period. Because stolen account information was reportedly exfiltrated to attackers through the Telegram API, rapid reporting of suspected phishing matters: the faster a suspicious email is flagged, the less time attackers have to move stolen credentials off-site. Techniques referenced in this campaign map to spearphishing via link (T1566.002), spearphishing attachment (T1566.001), and user execution of malicious files (T1204.001), which security awareness programs can use as a basis for targeted training scenarios.

Key findings

  • Phishing was the most prevalent initial access method for the financial sector in June, often followed by downloaders/droppers and then infostealers in multi-stage chains.
  • HTML attachments were the most common malicious attachment type, suggesting heavy use of HTML-based phishing pages and related techniques.
  • Korean-language attachment names were designed to look like real business documents (e.g., tax/payment receipts and HR/contract paperwork) to build trust.
  • Stolen account information gathered via malware infections and phishing emails was leaked to attackers via the Telegram API; phishing emails used themes like “money transfer,” “receipt,” and “voicemail.”
  • The report also highlights dark-web activity: alleged sales of leaked databases, ransomware/extortion victim claims, and sales of access credentials.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Treasury, HR, Procurement, Operations, Executive assistants.
  • Affected industries: Financial services, Insurance, Fintech, Banking, Asset management.
  • Attack channels: email, website.
  • Impersonated: A bank/payment service or internal finance system (masquerading as a legitimate login page), External business partner or internal HR/finance team (via a realistic-looking document filename).

Red flags to watch for

  • Unexpected message pressuring you to view a transfer/receipt/voicemail via a link or attachment
  • HTML attachment used as the ‘document’
  • Link/attachment leads to a login page that doesn’t match normal company sign-in flow
  • Attachment filename looks like a sensitive business document but arrives unexpectedly
  • Script-based attachment types (e.g., .js, .vbe) or web-document types (e.g., .html)
  • Sender context doesn’t match normal document exchange processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What phishing themes are being used against finance teams?

Attackers used routine business themes like money transfer notices, receipts, and voicemail alerts to get recipients to click links or open HTML attachments leading to fake login pages.

Why are HTML attachments a concern in this campaign?

HTML accounted for the largest share of malicious attachments, often paired with script-based extensions like js, vbe, vbs, bat, and hta, which are used to build convincing fake login pages.

What happens to stolen credentials in this campaign?

Stolen account information collected through malware infections and phishing emails was leaked to attackers through the Telegram API, allowing rapid off-site exfiltration.

Who is most targeted by these phishing lures?

Finance, accounting, treasury, HR, procurement, operations, and executive assistant roles are the primary targets, particularly within financial services, insurance, fintech, banking, and asset management.

Read the video transcript

You get an email: “Subject: Money transfer receipt, please review.” Looks routine, right? The email pushes you to click a link or open an HTML “receipt.” That opens a login page that looks like your bank or finance portal, but it’s fake. Here’s the nasty part: the moment you type your ID and password, that data can be shot straight out through the Telegram API and sold on dark‑web markets within minutes. If an email about money transfers, receipts, or voicemail asks you to log in from a link or HTML file, stop, report it as phishing and verify the request through our normal finance or HR channels.

Similar attacks

Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026