Digital security organization RESIDENT.NGO has uncovered a highly personalized phishing campaign targeting Telegram users in Belarus, Russia and Kazakhstan. One of the targets was a Belarusian activist living in Lithuania.
In July 2026, RESIDENT.NGO investigated a phishing message sent via Telegram to a Belarusian activist residing in Lithuania (according to Reform.news, this was Andrej Stryzhak). The link, sent in a Telegram secret chat from an unknown account registered in Kazakhstan, led to a fake Telegram page requesting the authentication code needed to log into the account. The link also contained the target’s phone number in encoded form. The activist recognized the attack and did not enter any information.
Experts found that the incident was part of a broader phishing campaign that had been active since at least October 2024. Records from Google Threat Intelligence (GTI) contained 64 unique phone numbers embedded in personalized links across seven domains: 55 Russian, seven Belarusian and two Kazakh phone numbers.
“Most likely, these numbers belonged to the intended targets of the campaign. However, the available records do not confirm that every link was actually sent to its intended recipient or that any account was ultimately compromised,” the researchers said.
RESIDENT.NGO describes in detail how the scheme operated.
The message, written in Russian, was disguised as a notification from Telegram support. It claimed that the user’s account had violated the platform’s rules and could be blocked unless the user followed a link to verify the account. Some Cyrillic letters in the text had been replaced with visually similar Latin or Greek characters to evade automated text detection, while invisible Unicode control characters were inserted into the greeting and closing. As a result, the message appeared normal to the recipient but could evade automated detection systems.
After the user clicked the link, a second message appeared claiming that an account verification attempt had not been completed, providing the time, device and geolocation of the login attempt. The victim was again instructed to verify the account via a link. The phishing page, designed to imitate web.telegram.org, displayed the victim’s phone number and a field for entering the authentication code. Once the victim opened the page, the attacker initiated a legitimate Telegram login attempt, prompting Telegram to send a genuine authentication code to the victim’s phone. The victim then entered the code on the phishing page, giving the attacker access to the account.
The links were highly personalized, with each one containing the victim’s phone number.
“We found no evidence of malware distribution, APK downloads, droppers or any other malicious payloads. Based on the available evidence, this part of the infrastructure was designed solely to intercept Telegram authentication codes in order to hijack user accounts,” the researchers noted.
RESIDENT.NGO does not attribute the operation to any specific cyber threat actor, but says the attack shares characteristics with account takeover campaigns that have repeatedly targeted Belarusian activists.
“At the time of writing, open-source intelligence on the reputation of the domains and IP address used did not allow for definitive conclusions. Nevertheless, the broader set of personalized links indicates that this infrastructure was not intended solely for the documented attack against a single activist,” the experts said.


