<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Telegram impersonation - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/telegram-impersonation/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Sat, 29 Mar 2025 09:28:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>Telegram impersonation - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>Scammers created thousand of fake websites mimicking Telegram</title>
		<link>https://www.osintafrica.net/scammers-created-thousand-of-fake-websites-mimicking-telegram/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scammers-created-thousand-of-fake-websites-mimicking-telegram</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Sat, 29 Mar 2025 09:22:57 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[Phishing recommendations]]></category>
		<category><![CDATA[phishing Telegram]]></category>
		<category><![CDATA[Telegram impersonation]]></category>
		<category><![CDATA[Telegram Scam]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=882</guid>

					<description><![CDATA[<p>A large phishing campaign against Telegram was detected. The threat actors created thousand of websites...</p>
<p>The post <a href="https://www.osintafrica.net/scammers-created-thousand-of-fake-websites-mimicking-telegram/">Scammers created thousand of fake websites mimicking Telegram</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="graf graf--p"><span style="color: #000000;">A large phishing campaign against <strong>Telegram</strong> was detected.</span></p>
<p class="graf graf--p"><span style="color: #000000;">The threat actors created thousand of websites mimicking Telegram.</span></p>
<p class="graf graf--p"><span style="color: #000000;">At the time of writing, thousand of users are impacted.</span></p>
<p class="graf graf--p"><span style="color: #000000;">The impact could lead to data theft such as <strong>PII, Financial lost</strong> and further.</span></p>
<p class="graf graf--p"><span style="color: #000000;">Most of the phishing domains are hosted under CLOUDFLARENET.</span></p>
<p class="graf graf--p"><span style="color: #000000;"><strong>CLOUDFLARE</strong> is offering free features such as fastest DNS resolver, Delivery Network (CDN), Free SSL certificate</span></p>
<p class="graf graf--p"><span style="color: #000000;">which makes the service the best choice for threat actors </span><span style="color: #000000;">to compromise the user, the user must enter his/her PII as a newly register user. Once done, the data will be sent to the malicious server and stored.</span></p>
<p class="graf graf--p"><span style="color: #000000;"><strong>The certificates</strong> used on the domains are either from Google Trust Services WE1 or CLOUDFLARE, INC. Cloudflare TLS Issuing ECC CA 1, with the availability time set between 2025–03–20–2025–06–18  w</span><span style="color: #000000;">hich means that the phishing domains might stay longer than expected .</span></p>
<p class="graf graf--p"><span style="color: #000000;">Taking a precaution such as taking down the domains will be the best approach to protect the users.</span></p>
<p class="graf graf--p"><strong><span style="color: #000000;">Some of the Phishing domains:</span></strong></p>
<p class="graf graf--p"><span style="color: #000000;">elegeqwt[.]kim</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegmvev[.]lat</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegtrwe[.]kim</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegcmzb[.]hair</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegzmcb[.]lat</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegzcmz[.]hair</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegqtre[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegzmbc[.]icu</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegbzmc[.]lat</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegmexv[.]icu</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegwrte[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegwret[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegbzmc[.]lat</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegmexv[.]icu</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegwrte[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegwret[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegrrm[.]fans</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegwrqt[.]monster</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegqtre[.]ren</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegjhgk[.]cam</span></p>
<p class="graf graf--p"><span style="color: #000000;">telegrwtq[.]ren</span></p>
<p class="graf graf--p"><strong><span style="color: #000000;">Recommendations:</span></strong></p>
<p class="graf graf--p"><span style="color: #000000;">The domains should be taken down.</span></p>
<p class="graf graf--p"><span style="color: #000000;">Blocked the domains if visible within your environment.</span></p>
<p class="graf graf--p"><span style="color: #000000;">In case a user clicked on any domain, reset the user’s password.</span></p>
<p class="graf graf--p"><span style="color: #000000;">For those who use Telegram, activate 2FA on Telegram.</span></p>
<p class="graf graf--p"><span style="color: #000000;">Set up a password policy</span></p>
<p class="graf graf--p"><span style="color: #000000;">In case a user entered financial information such Bank account number (Contact your bank and change the information ASAP)</span></p>
<p class="graf graf--p"><span style="color: #000000;">Scan the host to ensure that no malicious payload was downloaded.</span></p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/scammers-created-thousand-of-fake-websites-mimicking-telegram/">Scammers created thousand of fake websites mimicking Telegram</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">882</post-id>	</item>
	</channel>
</rss>
