Telegram Phishing Attack Exploits Authentication Workflows for User Session Hijacking

Telegram Phishing Attack Exploits Authentication Workflows for User Session Hijacking

First seen 9 Feb 2026, 13:02 UTC GbhackersCybersecuritynewsCybersecurity-Insiders 24.3

Article Content

Browse articles
ThreatCluster

A new phishing campaign targeting Telegram users has emerged, utilizing the platform's authentication workflows to hijack fully authorized user sessions. This attack differs from traditional methods by avoiding password harvesting and instead manipulating legitimate login processes. Users of Telegram are at risk as attackers gain access to their accounts without needing to steal credentials directly.

Timeline

2026-02-09
New phishing campaign reported targeting Telegram users
Recent
Attackers manipulate Telegram's authentication workflows