Telegram bots are being repurposed as phishing infrastructure, with attackers deploying automated Telegram bot accounts to collect credentials.
Overview
Telegram bots are being repurposed as phishing infrastructure, with attackers deploying automated Telegram bot accounts to collect credentials. The campaigns target European entities and corporate credentials, illustrating how threat actors weaponize legitimate bot ecosystems within messaging platforms to harvest sensitive data. This highlights an evolving risk where messaging services become vectors for credential theft and credential-serving infrastructure.
Related Threat Clusters
-
Telegram Mini Apps Exploited for Widespread Crypto Scams and Malware Distribution
Cybersecurity researchers have identified a large-scale fraud operation utilizing Telegram's Mini App feature, named FEMITBOT. This platform enables threat actors to run various scams, including fake cryptocurrency…
3 articles · Updated May 3, 2026 -
Cyber Fraud Operations Targeting Victims via Malicious APKs and Stock Market Scams
Delhi Police have arrested multiple individuals involved in cyber fraud schemes, including a stock market scam that defrauded victims of Rs 14 lakh and APK-based frauds totaling Rs 80,825. The stock market scam involved…
179 articles · Updated May 10, 2026 -
New Android Malware 'Sturnus' Steals Banking Credentials and Encrypted Chats
Cybersecurity researchers have identified a new Android banking trojan named Sturnus, capable of stealing banking credentials and accessing encrypted messages from apps like WhatsApp, Telegram, and Signal. The malware…
48 articles · Updated December 2, 2025 -
New Android Malware 'Sturnus' Steals Banking Credentials and Encrypted Chats
Cybersecurity researchers have identified a new Android banking trojan named Sturnus, which can steal banking credentials and access encrypted messages from apps like WhatsApp, Telegram, and Signal. This malware…
1 article · Updated November 29, 2025 -
Phishing Campaign Targets European Organizations Using HTML Attachments and Telegram Bots
A sophisticated phishing campaign has been identified in Central and Eastern Europe, targeting various sectors including manufacturing and government. Cybercriminals are using HTML attachments with embedded JavaScript…
3 articles · Updated November 12, 2025 -
HTML Attachment Phishing and Telegram Bots Target European Organizations
A sophisticated phishing campaign has been identified in Central and Eastern Europe, targeting various sectors including manufacturing, government, and telecommunications. The campaign utilizes HTML attachments…
3 articles · Updated November 12, 2025
Recent Intelligence Reports
- Cyber Cell busts AI-driven deepfake loan fraud racket, three more masterminds arrested — English.Gujaratsamachar · May 9, 2026
- Telegram Mini Apps abused for crypto scams, Android malware delivery — Bleepingcomputer · May 3, 2026
- NFC Relay Malware Surge Targets European Payment Cards — Technadu · December 2, 2025
- Telegram bots exploited in European credential phishing campaign — Scworld · November 12, 2025
- Cyble Detects Phishing Campaign Using Telegram Bots to Siphon Corporate Credentials — Thecyberexpress · November 11, 2025