Tag: Phishing
-
A Telegram of Trouble: Tracking a regional OTP-phishing infrastructure targeting users in Russia, Belarus and Kazakhstan for 2 years
In July 2026, RESIDENT.NGO investigated a Telegram phishing message sent to a Belarusian activist living in Lithuania. The link led to a fake Telegram page that asked for a login code. The link also contained the target’s phone number in encoded form. After examining that site, we searched for other pages built and operated in…
-
Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist
In July 2026, RESIDENT.NGO investigated a cloaked phishing operation targeting the Telegram account of an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time.
-
Case Study — UNC1151 Gmail Phishing (“Suspicious account activity”) Targeting Belarusian Pro-Democracy Politician, May 2026
On 29 May 2026, an individual involved in the Belarusian democratic movement received an email in Russian pretending to be from Google. It claimed the account showed “suspicious activity” and would be deleted within 24 hours unless it was “verified.” The target recognized the message as suspicious and shared a sample with RESIDENT.NGO ThreatLab. We…
-
Technical Writeup: Signal Account Takeovers Phishing Campaign Targets Exiled Belarusian Activists 2025
This writeup details a targeted Signal Account Takeover (ATO) Phishing Campaign identified by RESIDENT.NGO. The campaign utilizes spear phishing conducted in Polish or English via Signal Messenger and targets Belarus-related public figures and media workers residing outside of Belarus. The goal is to trick users into surrendering their 6-digit SMS Signal registration verification code, leading…