Phish Lures Steal Bank Logins via Telegram

AhnLab ASEC · Medium sophistication
Last updated August 24, 2026

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing dark web data-sale claims and hacktivist DDoS activity, but the most simulation-ready detail is the phishing-to-credential-theft workflow.

Key findings

  • Phishing was the top initial access method observed for attacks against the financial sector, and multi-stage chains starting with phishing were described as common.
  • Victims were lured to login pages via phishing emails, malicious links, or HTML attachments; entered IDs/passwords were leaked to Telegram using APIs.
  • Phishing campaigns used keywords including “money transfer,” “receipt,” and “voicemail.”
  • Korean-language attachment filenames commonly masqueraded as business documents, tax/payment receipts, HR documents, and contract documents.
  • The report also summarizes dark web data-sale claims involving major financial brands and mentions hacktivist DDoS activity, though not all claims were verified.

Who’s being targeted

  • Commonly targeted roles: All employees in financial services, Finance and payments teams, Back-office operations, Helpdesk/service desk (credential reset requests may follow phishing).
  • Affected industries: Banking, Financial services, Insurance.
  • Attack channels: email.
  • Impersonated: Internal business operations or a payments/receipts sender (generic business document source), Voicemail/telephony service (generic).

Awareness takeaways

  • Treat HTML attachments as high-risk, do not open them from unsolicited financial emails (receipts, tax, HR, contracts).
  • If an email leads you to a login page (especially after clicking a link or opening an attachment), stop and verify via a trusted channel before entering credentials.
  • Be extra cautious with common ‘urgent action’ lures like money transfers, receipts, and voicemail notifications, these keywords are actively used in phishing.

Red flags to watch for

  • An HTML attachment is used for a “document/receipt,” which is unusual
  • The page asks for credentials after opening an attachment
  • Urgent finance-themed wording like “receipt” or “payment” used to prompt quick action
  • Generic “voicemail” lure that routes to a login page
  • Unexpected login prompt reached via email link
  • Credential capture is the goal (ID/password requested)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: subject line just says, “Receipt.” There’s an HTML file attached and it looks like a payment document. You open it, and a login page pops up asking for your bank or email ID and password to view the receipt. The moment you type them, those credentials are shot straight to a Telegram chat via an API. Same trick with “Voicemail” emails: you click a link, land on a login page, and your ID and password are quietly relayed to Telegram. The common pattern? Email about money, receipts, or voicemail that suddenly demands a login. Your move: if an email or HTML attachment sends you to a login page, stop. Don’t type anything, go to the site yourself from your browser and log in there instead.

Similar attacks

Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Finance Phishing Lures Feed Telegram Data Leaks

Finance Phishing Lures Feed Telegram Data Leaks

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information…

July 22, 2026