Mon 27 Jul 2026 / 15:18 ET
Kernel
Security 3 min read

Telegram phishing targeted Belarusian activist, researchers say

Resident NGO says attackers used tailored Telegram lures to try to steal one-time login codes from users in Belarus, Russia and Kazakhstan.

Dana Voss

By Dana Voss / Security Correspondent

Telegram phishing targeted Belarusian activist, researchers say
img: The Record

A telegram phishing Belarusian activist campaign used highly tailored messages to try to seize accounts without installing malware, according to two reports from the digital security group Resident NGO. The group said at least one exiled Belarusian activist in Lithuania was targeted, and that related infrastructure appears to have been aimed at users in Belarus, Russia and Kazakhstan since at least October 2024.

Resident NGO said the attempted attack started inside Telegram’s secret chat feature, which uses end-to-end encryption. The target received a message from an unknown account tied to a Kazakhstani phone number. The message posed as a Telegram safety notice, claimed the user had broken platform rules and threatened an account block unless the user followed a verification link.

One intended victim spotted the lure, did not submit credentials and sent the messages to Resident NGO for analysis, the researchers said.

How did the Telegram phishing campaign work?

The attackers were trying to capture Telegram one-time login codes, according to Resident NGO. Telegram uses those codes to authorize account access. If a victim typed the code into the fake page before it expired, the operators could use it to take over the account.

Resident NGO said the phishing URLs were personalized. Each link included the target’s phone number, which let the operators identify who opened it. Researchers found 64 separate phone numbers embedded in links, most of them Russian numbers. The group cautioned that the records show likely targets, not proof that every link was delivered or that any account was compromised.

The fake login page was only one part of the setup. Resident NGO said the infrastructure checked a visitor’s browser and device before deciding what to show. A visitor matching the intended profile would see a counterfeit Telegram login flow. Many desktop users and security tools were instead sent to Telegram’s real site or to benign pages, a filtering trick meant to keep researchers and automated scanners from seeing the phishing kit.

The operators also appeared to watch link openings in real time, according to the reports. After a target visited the page, the same campaign sent another message saying verification was incomplete and warning of suspicious activity. That follow-up included the person’s device details, the time the link had been opened and the internet service provider, data collected from the visit. Resident NGO said the goal was likely to make the warning look more convincing and push the user to finish the fake login.

To make automated detection harder, the researchers said, the attackers altered some Cyrillic text by swapping in visually similar Latin and Greek characters. That kind of character substitution can preserve the look of a message for a human reader while frustrating basic text-matching filters.

What is still unknown?

Resident NGO said it could not determine the total number of people targeted, whether any accounts were taken over or what the operators planned to do with any accounts they obtained. The group said the methods fit a pattern of account-hijacking activity directed at Belarusian civil society.

Those communities have faced more technically invasive operations as well. In 2024, Access Now and Citizen Lab reported that at least seven Russian- and Belarusian-speaking journalists and opposition activists in Latvia, Lithuania and Poland had been targeted with Pegasus spyware. Reporters Without Borders also disclosed ResidentBat, a previously unknown spyware tool found on the phone of a Belarusian journalist who believed it had been installed while they were detained by Belarus’ KGB.

Resident NGO’s conclusion is blunt enough: malware is not required when a private message is specific, timely and credible enough to make a target hand over the key to an account.

This story draws on original reporting from The Record.

More Security/

view all ↗