Phish Lures Steal Bank Logins via Telegram

AhnLab ASEC · Medium sophistication
Last updated August 24, 2026

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing dark web data-sale claims and hacktivist DDoS activity, but the most simulation-ready detail is the phishing-to-credential-theft workflow.

Key findings

  • Phishing was the top initial access method observed for attacks against the financial sector, and multi-stage chains starting with phishing were described as common.
  • Victims were lured to login pages via phishing emails, malicious links, or HTML attachments; entered IDs/passwords were leaked to Telegram using APIs.
  • Phishing campaigns used keywords including “money transfer,” “receipt,” and “voicemail.”
  • Korean-language attachment filenames commonly masqueraded as business documents, tax/payment receipts, HR documents, and contract documents.
  • The report also summarizes dark web data-sale claims involving major financial brands and mentions hacktivist DDoS activity, though not all claims were verified.

Who’s being targeted

  • Commonly targeted roles: All employees in financial services, Finance and payments teams, Back-office operations, Helpdesk/service desk (credential reset requests may follow phishing).
  • Affected industries: Banking, Financial services, Insurance.
  • Attack channels: email.
  • Impersonated: Internal business operations or a payments/receipts sender (generic business document source), Voicemail/telephony service (generic).

Awareness takeaways

  • Treat HTML attachments as high-risk, do not open them from unsolicited financial emails (receipts, tax, HR, contracts).
  • If an email leads you to a login page (especially after clicking a link or opening an attachment), stop and verify via a trusted channel before entering credentials.
  • Be extra cautious with common ‘urgent action’ lures like money transfers, receipts, and voicemail notifications, these keywords are actively used in phishing.

Red flags to watch for

  • An HTML attachment is used for a “document/receipt,” which is unusual
  • The page asks for credentials after opening an attachment
  • Urgent finance-themed wording like “receipt” or “payment” used to prompt quick action
  • Generic “voicemail” lure that routes to a login page
  • Unexpected login prompt reached via email link
  • Credential capture is the goal (ID/password requested)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: subject line just says, “Receipt.” There’s an HTML file attached and it looks like a payment document. You open it, and a login page pops up asking for your bank or email ID and password to view the receipt. The moment you type them, those credentials are shot straight to a Telegram chat via an API. Same trick with “Voicemail” emails: you click a link, land on a login page, and your ID and password are quietly relayed to Telegram. The common pattern? Email about money, receipts, or voicemail that suddenly demands a login. Your move: if an email or HTML attachment sends you to a login page, stop. Don’t type anything, go to the site yourself from your browser and log in there instead.

Similar attacks

EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
China-Linked Phishers Target AI Policy Experts

China-Linked Phishers Target AI Policy Experts

Researchers reported two China-aligned campaigns that used phishing and impersonation to target AI policy experts and multiple Asian government organizations. One campaign built rapport with “AI policy” themed outreach before sending links to a OneDrive credential-harvesting page, while another…

October 1, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026