Cybersecurity researchers point to the growth of the phishing ecosystem due to the emergence of Telegram as an epicenter for the cybercrime space, allowing perpetrators to launch massive attacks for as little as $230.
See also: Telegram update brings voice transcription to everyone

This is not the first time the popular platform has come under scrutiny for facilitating malicious activity, which is partly due to its lax management efforts.
As a result, what was once only available in closed forums on the Dark Web is now widely accessible through public channels and groups, thus opening the gates of cybercrime to emerging and experienced cybercriminals.
In April 2023, Kaspersky revealed how scammers are creating channels on Telegram to educate new users about phishing and promote bots that can automate the process of creating phishing pages to collect sensitive information, such as login credentials.
One of the malicious bots on Telegram is Telekopye (also known as Classiscam), which can create large-scale scams through fake websites, emails, and SMS, with the aim of deceiving users.
Guardio said that the building blocks to construct a phishing attack can be easily purchased from Telegram – “some are offered at very low prices and some are even free” – making it possible to create scam pages via a phishing kit, host it on a compromised WordPress website via a web shell, and use a backdoor mailer to send the emails.
See also: Google Play: Fake Telegram apps infected users with spyware
Backdoor mailers, promoted in various Telegram groups, are PHP scripts that are embedded in already infected but legitimate websites to send convincing emails using the legitimate domain of the exploited website, bypassing spam filters.

To further increase the likelihood of such campaigns being successful, digital marketplaces on Telegram also provide what are called “letters,” which are “professionally designed, branded templates” that make emails look as authentic as possible to trick victims into clicking on the fake link that leads to the scam page.
Telegram also has large datasets of valid and relevant email and phone numbers for targeting. They are called “prospects” and are sometimes “enriched” with personal information, such as names and physical addresses, to increase their impact.
The way these lead lists are prepared can vary from vendor to vendor. They can be sourced either from cybercriminal forums selling data stolen from compromised companies, or through suspicious websites that encourage visitors to complete a fake survey to win prizes.
Another critical element of these phishing campaigns is a way to exploit the stolen credentials gathered by selling them to other criminal groups in the form of “logs,” ensuring threat actors a return of ten times their investment, based on the number of victims who end up providing valid information to the scam page.
See also: Telegram 10.5.0 update: Improved Calls, Brand New Experience
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What are the consequences of buying phishing attacks from Telegram?
Purchasing phishing attacks from Telegram can have several serious consequences. First, users who purchase these attacks may be exposed to legal penalties, as using them for illegal purposes is illegal.
Second, users who purchase phishing attacks may be exposed to other malicious users. This can happen if the seller is malicious themselves and uses the information provided to carry out attacks against the buyer.
Third, the market for phishing attacks can lead to an increase in cybercrime. This is because the availability of these attacks makes it easier to carry out cybercrimes, which can lead to an increase in overall cybercrime.
Finally, the market for phishing attacks can have a negative impact on user trust in the internet. This can lead to a decrease in the use of digital services and limit technological progress.
Source: thehackernews
