Skip to main content
Advertisement
Live broadcast
Main slide
Beginning of the article
Озвучить текст
Select important
On
Off

Scammers have begun actively using the news around Telegram and Pavel Durov (listed as a terrorist and extremist in the Russian Federation) to spread new phishing schemes related to the Gram cryptocurrency. Users are offered to urgently exchange old tokens, withdraw funds before the supposedly upcoming blocking of the messenger, or receive free cryptocurrency through special services. According to experts, the attackers create fake websites and Telegram bots designed in the official style of the platform. The main instruments of influence are the fear of losing money and the promise of easy earnings.

Fake Telegram Services

After the news about Telegram appeared, cybersecurity experts recorded a sharp increase in suspicious activity. According to them, the attackers began to massively register domains mentioning Telegram, Pavel Durov, and the Gram cryptocurrency, the native token of the TON blockchain, as well as launch fake services promising users to retain access to assets or make quick money on a new "coin."

— After July 30, SBA analysts have recorded an increase in registration activity around Telegram. In six days, the number of new domains mentioning Telegram or Durov increased by about 18%. At the same time, the number of domains with potential signs of phishing has doubled. Especially noticeable is the batch registration on August 3 of 11 domains of the same type at once, masquerading as Telegram verification and protection services," Sergey Trukhachev, head of the Smart Business Alert service at ESA PRO, told Izvestia.

Photo: IZVESTIA/Alexander Kazakov

According to him, scammers are actively exploiting user fears related to the future of Telegram. People are being convinced that the services affiliated with the founder of the messenger will allegedly soon be unavailable, so it is necessary to transfer funds as soon as possible or use a new cryptographic service.

Criminals almost immediately began using information to create new legends, said Pavel Kovalenko, director of the anti-fraud center at Informzashita. According to him, the launch of the built-in non-custodial Gram wallet opened additional opportunities for attackers. Users have not yet had time to figure out the new feature, which is actively used by scammers, posing fake services as official Telegram tools.

Photo: IZVESTIA/Anna Selina

Fedor Chunizhekov, head of the Positive Technologies research group, gave a similar assessment. He noted that high-profile events traditionally become the basis for new scenarios of social engineering.

— The user is informed that it is necessary to "urgently confirm the account", "withdraw assets before blocking", "exchange old coins", "get free tokens" or "register for a new service before the others". It is the sense of urgency, the promise of free benefits, and the exclusivity of the offer that become the main tools of manipulation and psychological pressure," he explained.

Systemic approaches of scammers

The main task of scammers is to convince a person to provide access to their crypto wallet on their own. After clicking on the link, the user is asked to log in via Telegram, enter a seed phrase or confirm the transaction, after which the assets are irrevocably transferred to the attackers, Pavel Kovalenko said.

In fact, criminals rely not on hacking technologies, but on psychological pressure, added Igor Bederov, chairman of the Council for Countering Technological Offenses of the National Security Council of Russia, founder of the Internet Search company.

Scammers do not hack complex blockchain protocols, they hack credulity and craving for "freebies" against the background of panicked headlines. In addition, the number of registrations of phishing domains with the words gram, wallet, convert and gift in conjunction with Telegram has increased tenfold," the expert emphasized.

Photo: IZVESTIA/Eduard Kornienko

At the same time, fraudulent campaigns are becoming more and more complex. Today, attackers are building entire chains of trust, consistently transferring users from search results to the Telegram channel, then to a bot and to a fake website, said Mikhail Shurygin, chairman of the ROCIT commission on cloud technologies, hosting and information security.

— We can talk about the transition from the primitive distribution of malicious links to the creation of entire "ecosystems of false trust," he said.

High-quality design, reviews, support services, and even a secure connection are no longer considered signs of resource reliability. It is important for users to remember that telegram and its official services do not distribute cryptocurrencies or convert tokens through third-party websites or bots, the expert recalled.

Photo: IZVESTIA/Sergey Lantyukhov

The attackers also actively use phishing pages and cryptograiners, malware that encourages users to connect crypto wallets to fake websites on their own or enter credentials from Telegram under the pretext of receiving free tokens and other bonuses, added Maria Sinitsyna, senior analyst at the Digital Risk Protection department at F6.

— The main vulnerability in 99% of such attacks is at the junction of technology and human psychology, — said Igor Bederov.

The experts surveyed agree that caution remains the main protection of digital assets. They recommend that you do not follow advertising links, do not enter seed phrases and confirmation codes on third-party resources, and use only official Telegram services when working with crypto wallets.

Переведено сервисом «Яндекс Переводчик»

Live broadcast