{"id":10498,"date":"2026-02-09T10:04:12","date_gmt":"2026-02-09T10:04:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/09\/new-telegram-phishing-attack-abuses-authentication-workflows-to-obtain-full-authorized-user-sessions\/"},"modified":"2026-02-09T10:04:12","modified_gmt":"2026-02-09T10:04:12","slug":"new-telegram-phishing-attack-abuses-authentication-workflows-to-obtain-full-authorized-user-sessions","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/09\/new-telegram-phishing-attack-abuses-authentication-workflows-to-obtain-full-authorized-user-sessions\/","title":{"rendered":"New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions"},"content":{"rendered":"<p>    New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. <\/p>\n<p>Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform\u2019s legitimate authentication infrastructure. <\/p>\n<p>By integrating directly with Telegram\u2019s official login workflows, the attackers can bypass standard security filters and obtain fully authorized user sessions without raising immediate alarms.<\/p>\n<p>The attack vectors are designed to minimize user suspicion by mimicking routine security checks and verification procedures. <\/p>\n<p>Victims are presented with fraudulent login interfaces that support both <a href=\"https:\/\/cybersecuritynews.com\/emerging-cyber-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">QR-code scanning<\/a> and manual phone number entry.<\/p>\n<p>These interfaces are hosted on ephemeral domains that closely resemble legitimate Telegram branding. <\/p>\n<p>When a user interacts with these elements, they are not sending data to a hacker\u2019s database but are inadvertently triggering a real login request initiated by the attacker\u2019s device.<\/p>\n<p><a href=\"https:\/\/www.cyfirma.com\/research\/re-emerging-telegram-phishing-campaign-targeting-user-authorization-prompts\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cyfirma analysts identified this malware<\/a> after observing its unique ability to frame authorization prompts as security verifications.<\/p>\n<p>The researchers noted that this method significantly increases victim compliance while reducing detectable anomalies. <\/p>\n<p>Once the user approves the request on their mobile device, believing they are verifying their identity, the attackers gain immediate, persistent access to the account. <\/p>\n<p>This allows them to monitor communications and launch secondary attacks against the victim\u2019s contacts without alerting the user through typical suspicious login warnings or requiring exploit-based access.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-dynamic-infrastructure-and-api-abuse\"><strong>Dynamic Infrastructure and API Abuse<\/strong><\/h2>\n<p>The technical sophistication of this campaign is evident in its use of dynamic backend configurations to evade detection. <\/p>\n<p>Rather than hardcoding phishing logic into the frontend HTML, the site retrieves runtime instructions from a centralized server via cross-origin API requests. <\/p>\n<p>This JSON response delivers attacker-controlled <a href=\"https:\/\/cybersecuritynews.com\/here-is-how-analysts-use-telegram-api-to-intercept-data-exfiltrated-by-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram API credentials<\/a>, such as the\u00a0<code>api_id<\/code>\u00a0and\u00a0<code>api_hash<\/code>, along with localized language data to render the login interface.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgYbODq9lSrVUxpd-a1Cx6cLMxT6wErjz10suz-4GdrPQ-wjeiXxCKdqsrmcqxPeeuTbnnnF_LjiyyAAqEEeXZtUxIA6-UNtIeikHHvfWWkVLMS-E-XOeRSEwO19oE6ANLNBv2kEnokaL1wcy8F6lrxREDqaO8A68Sak0PMoxqKTDIxQ6BMekfxWXS7PvQ\/s16000\/In-app%2520authorization%2520prompt%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"In-app authorization prompt (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">In-app authorization prompt (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>This configuration-driven design allows the operators to rapidly rotate domains while maintaining consistent authentication logic across globally distributed targets. <\/p>\n<p>The phishing pages also display misleading system messages, instructing users to click \u201cYes\u201d on the in-app notification to \u201cverify\u201d their account. <\/p>\n<p>By shifting the decisive action to the trusted Telegram app interface, the campaign successfully masks the malicious nature of the session binding process.<\/p>\n<p>To mitigate these risks, users must exercise extreme caution with in-app authorization prompts. <\/p>\n<p>Never approve a login request unless you personally initiated it, even if the prompt claims to be a security check or unusual activity review. <\/p>\n<p>It is essential to avoid scanning QR codes from unfamiliar websites and to regularly audit active sessions within Telegram\u2019s \u201cDevices\u201d settings. <\/p>\n<p>Finally, enabling <a href=\"https:\/\/cybersecuritynews.com\/two-factor-authentication\/\" id=\"7192\" target=\"_blank\" rel=\"noreferrer noopener\">Two-Step Verification<\/a> adds a critical layer of defense, preventing unauthorized session creation by requiring a secondary password even if a user is tricked into approving the initial prompt.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-telegram-phishing-attack-abuses-authentication-workflows\/\">New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-telegram-phishing-attack-abuses-authentication-workflows\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform\u2019s legitimate authentication infrastructure. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10498","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10498"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10498"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10498\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}