
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled Belarusian activist and users in Russia and Kazakhstan. Victims were pushed to click a personalized link and enter Telegram’s one-time login code (OTP), which would allow attackers to immediately take over the account. The campaign used anti-detection tricks (device checks, redirects, look‑alike characters) and follow-up pressure messages to increase success.
The operation began with a fake Telegram security alert sent through the app's own end-to-end encrypted secret chat feature, from an unfamiliar account. The message claimed the recipient had violated Telegram's rules and warned that the account would be blocked unless they clicked a link to verify it. Instead of delivering malware, the goal was simpler and faster: trick the victim into entering Telegram's one-time login code (OTP) on a fake page. If the victim entered the code before it expired, attackers could immediately take over the account.
Each phishing link was individualized and included the target's phone number, letting operators track exactly who opened it. After a click, operators followed up with a second message claiming verification was still incomplete and citing suspicious activity, along with details about the victim's device, click time, and internet service provider, information collected the moment the link was opened.
Several factors made this campaign effective against specific, high-value targets:
Treat any message warning of imminent account suspension as suspicious, especially from unknown senders. Never enter an OTP into a page reached via a chat link. Verify account status only through official in-app security settings. Because attackers can tailor pages to evade automated scanners and disguise text with look-alike characters, absence of an automated warning does not mean a message is safe, human judgment remains the last line of defense for high-risk users such as journalists, activists, and communications staff.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers sent a fake security alert through a Telegram secret chat claiming the account would be blocked unless the victim clicked a link and entered their one-time login code. Entering that code allowed attackers to immediately take control of the account, no malware required.
The phishing infrastructure checked each visitor's browser and device, showing the fake login page only to intended targets while redirecting security tools and unrelated visitors to Telegram's real site or other harmless pages. Messages also swapped in look-alike Latin and Greek characters to evade automated text detection.
After a target clicked the link, operators sent a second message citing details like device type, click time, and ISP that were collected when the link was opened. This was likely meant to make the warning look legitimate and pressure the victim into completing the fake verification.
Do not click the link or enter any one-time code sent through chat. Verify account status directly through Telegram's official in-app security settings instead.
Imagine this: a Telegram secret chat pops up, claiming you broke the rules and your account will be blocked unless you verify it now. The link they send is customized with your phone number. You tap it, and a perfect Telegram login page appears, asking for the one-time code just sent to your phone. The moment you type that OTP, they can hijack your account, no malware, no password needed. Here’s the creepy part: after you click, they send a second message quoting your device, time, even your internet provider to sound legit and push you to finish. Tools might see only real Telegram pages, but you see the trap. Your move: if any Telegram chat, especially an unknown secret chat, asks you to enter a one-time code from a link, stop and check your account only through Telegram’s official app settings.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…