Telegram's anonymous blogging platform, Telegraph, is being actively exploited by phishing actors who exploit the platform's lax policies to create intermediary landing pages that lead to account credentials theft.

See also: Intuit warns QuickBooks customers that they are being targeted in phishing attacks
Telegraph is a blogging platform that allows anyone to post anything without creating an account or providing any identifying information.
While this provides anonymity to the publisher, it also allows for widespread abuse by threat actors for their own campaigns.
Published Telegraph posts create a link that threat actors can distribute in any way they choose, but there is no central location to promote these posts to the community. As such, the Telegraph platform is fast, simple, and anonymous.
Additionally, because Telegraph's editor supports adding images, links, and offers text formatting options, one could make a post look like a web page, including login forms.
Phishing pages
According to an INKY report shared with Bleeping Computer prior to publication, the operators of the phishing campaign are using Telegram's platform – Telegraph – extensively to create phishing sites that resemble website landing pages or login portals.
INKY data from late 2019 to May 2022 shows that the inclusion of Telegraph links in phishing emails is on the rise, with over 90% of all detections occurring this year.
See also: Hackers target Russian government with phishing attacks
Phishing email delivery rates are excellent because these links are hosted on Telegraph, a platform that is not flagged as dangerous or suspicious by any email security solution.
In many cases, INKY observed that phishing emails came from compromised email accounts, so blocklists on known scam addresses were bypassed.
In most of the recorded cases, the goal of phishing actors is to commit cryptocurrency fraud or collect the account credentials of their targets.
The cases observed by INKY vary widely, indicating that Telegraph abuse comes from multiple groups/actors rather than one specific threat cluster.
An example is a OneDrive notification that leads to a realistic-looking Microsoft login page , where the victim is asked to enter their account credentials .


In another case, INKY saw a message threatening to leak private files if the recipient did not pay the ransom. The payment gateway is hosted directly on Telegraph, offering multiple payment options for scammed victims.

How to protect yourself
Hackers are constantly experimenting with new tactics that can increase their chances of success. They often achieve this goal by combining stolen email and free websites like the Telegraph.
For this reason, users should not trust an email just because it went through security. If it has a link in the body of the text, hover over it to see where it redirects before clicking.
See also: Phishing sites use chatbots to steal credentials
Whenever you land on a website that asks for your account credentials, confirm that you have reached the official login portal before typing anything into the boxes.
Information source: bleepingcomputer.com
