Telegram bots are used to steal one-time passwords required for two-factor authentication (2FA) security.

See also: Telegram: How to move or backup secret chats on Android?
On Wednesday, researchers from Intel 471 said they have seen an "increase" in the number of these services being offered in the internet's underground, and in recent months, it appears that the variety of 2FA circumvention solutions has been expanding - with bots becoming a favorite choice.
Two-factor authentication (2FA) can be receiving one-time passwords (OTPs), codes, links, biometrics, or touching a physical dongle to confirm the account holder's identity. Most often, 2FA tokens are sent via text message to a handset or email.
While 2FA serves to improve the protection of our accounts with the use of passwords, threat actors have been quick to develop methods to intercept OTPs, such as through malware or social engineering.
See also: Twitter: New tag allows accounts to identify themselves as bots
According to Intel 471, since June, a number of 2FA bypass services have been abusing the Telegram messaging service. Telegram is either used to create and manage bots or as a central “customer support” channel for cybercriminals performing such operations.
Telegram bots are used to automatically call potential victims in phishing attempts, send messages claiming to be from a bank, and try to lure victims into handing over OTP passwords. Other bots target social media users in phishing and SIM-swap attempts.
Creating a bot requires a basic level of programming – but nothing compared to developing custom malware, for example. What makes matters worse is that in the same way as traditional botnets, Telegram bots can be rented – and once a victim’s phone number is submitted, attacks can be launched with just a few clicks.
The researchers reported two particularly interesting bots: SMSRanger and BloodOTPbot.
SMSRanger's interface and command setup are similar to the collaboration platform Slack and can be used to target specific services, including PayPal, Apple Pay, and Google Play. BloodOTPbot is an SMS-based bot that can also be used to create automated calls impersonating bank staff.
See also: Cybercriminals are leaving the dark web and "moving" to Telegram
In April, Check Point Research revealed the existence of a Remote Access Trojan (RAT) dubbed ToxicEye that abuses the Telegram platform, leveraging the communication service within the command-and-control (C2) infrastructure.
Information source: zdnet.com
