
APT Lures Shift to Jobs, Code Reviews, Cloud Apps
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…
Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations, clicking phishing links, and later carrying out arson or armed attacks. The alleged scheme started with romance-style outreach and payments via phishing links, then escalated to intimidation calls/messages impersonating Russian authorities. The article provides a step-by-step workflow that can be adapted into realistic awareness simulations.
This case describes a two-phase social engineering operation that allegedly began on a Telegram dating chatbot. Agents posed as young women to build romantic relationships with targets, then asked them to share their geolocation for a meeting and to pay for movie tickets, concert tickets, or gifts through phishing links. This first phase relied on trust built through ordinary romantic chat, making the payment request feel like a normal next step rather than a scam.
The second phase shifted the pretext entirely. Impostors posing as Russian law enforcement authorities or officials from Rosfinmonitoring contacted the same targets through messaging apps, claiming that the money they had sent earlier had ended up funding hostile military activity. Under threat of criminal prosecution, targets were allegedly coerced into pseudo-operational tasks, including arson and armed attacks.
The scheme worked by combining two very different manipulation styles in sequence. The romance phase lowered defenses through emotional investment, making a request to click a link or share a location feel routine. The authority-impersonation phase then used fear and legal threats to override critical thinking. Targets were reportedly left unable to critically assess the situation due to psychological pressure, which is a common outcome when urgency and intimidation are layered on top of an existing relationship of trust.
Awareness efforts should emphasize that legitimate authorities do not conduct financial investigations through casual messaging apps and do not threaten immediate prosecution to compel action. People should be encouraged to pause before clicking payment links shared by online contacts and to verify any claimed law enforcement contact through channels they look up themselves, not ones provided by the person contacting them. Training should also highlight that emotional pressure, whether romantic or fear-based, is a manipulation signal in itself. When a conversation moves from small favors to high-stakes demands, that shift is worth treating as a red flag rather than a natural escalation of trust.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Agents allegedly posed as young women on the Daivinchik/Leo dating chatbot to build romantic relationships with targets, then asked for their location and pushed them to pay for gifts or tickets through phishing links.
After the romance phase, impostors allegedly posed as Russian law enforcement or Rosfinmonitoring officials and claimed the targets' payments had funded a hostile military, then used threats of criminal prosecution to coerce them into pseudo-operational tasks including arson and armed attacks.
Warning signs include a new online romantic contact quickly asking for payment via an unfamiliar link, requests to share a precise meeting location, and unexpected messages from people claiming to be authorities who threaten prosecution to force immediate compliance.
The scenario targeted young Russian men through a dating chatbot, but the underlying tactics apply broadly to students, young adults, and general users of messaging apps who interact with unknown online contacts.
Imagine this: a Telegram dating bot, Daivinchik, flirts with you… and weeks later someone’s ordering you to commit a crime. FSB says Ukrainian agents used this bot to masquerade as young women, build romance, then ask for your geolocation and for you to buy movie or concert tickets through a phishing link. Then phase two: someone messages you on Telegram, claiming to be Russian law enforcement or Rosfinmonitoring, saying your ticket payment funded the Armed Forces of Ukraine and threatening prosecution unless you ‘cooperate.’ Your move: if a new online romance sends payment links or anyone on Telegram claims to be law enforcement and threatens you, stop, don’t click, and verify using official contacts you look up yourself.

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was…

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…