- Статьи
- Internet and technology
- On the phishing line: scammers use the new function of sending applications in messengers
On the phishing line: scammers use the new function of sending applications in messengers
Scammers have found a new way to deceive users through the function of sending applications in messengers. In particular, with the advent of Telegram's ability to embed programs in messages, attackers began sending fake games and promotions, the inclusion of which activates malware and steals data. Previously, these applications were available via links. The user to whom the program is sent in this way does not need to click on links or download additional files. What other methods of deception have become popular can be found in the Izvestia article.
How fraudulent services disguise themselves as Telegram
The Telegram update of August 25 expanded the capabilities of messages: they now have support for embedded applications, polls, and games. Scammers have already started using this by sending out fake quizzes and promotions. Running them can lead to the installation of malware and theft of user data. The user does not have to go to a suspicious site or download a file. It is enough to click on the button in the message, which looks like a regular messenger function, and confirm the action with authorization. After that, attackers can gain access to the account.
"We are entering a phase when messengers are no longer just a means of communication and become a full—fledged software launch space," said Igor Bederov, Chairman of the Council for Combating Technological Offenses of the National Security Council of Russia, founder of the Internet Search company.
According to him, scammers are moving from ordinary phishing links to using the messenger ecosystem. In particular, they can copy the interfaces of banks, payment systems, and crypto exchanges. The user sees the familiar "Confirm transfer" button, but is actually interacting with a malicious script.
An additional threat is the ability to automatically place the specified text in the clipboard, added Sergey Trukhachev, head of the Smart Business Alert service at ESA PRO. For example, a person may be shown a message about an alleged error and prompted to click the "Copy Fix" button, and then paste the received command into an executing PowerShell process. In this case, the user performs the malicious action independently.
— At the same time, we are not necessarily talking about infecting the device. Fraudsters can use psychological manipulation and force a person to transfer confidential data on their own. Among the common schemes are fake votes, where, under the pretext of fraud protection, the user is asked to provide a phone number and a confirmation code," explained Georgy Kucherin, senior expert at Kaspersky GReAT Kaspersky Lab.
Information technology expert Sergey Pomortsev noted that such schemes are typical not only for Telegram. According to him, large messengers, including WhatsApp (owned by Meta, which is recognized as extremist and banned in Russia) and WeChat also remain attractive to cybercriminals. At the same time, Telegram has often set technological trends in recent years, which are then adopted by competitors, so similar fraudulent scenarios may appear on other platforms.
How not to become a victim of scams
The new schemes complicate the work of traditional security tools, since a malicious script may not contain a regular link or executable file.
"If the user enters the confirmation code, card details, connects a crypto wallet or signs a transaction, the antivirus may not see anything unusual," said Pavel Kovalenko, director of the Informzashita anti—fraud center.
According to him, a significant part of the attacks are still based on links and bots, but the WebView mode built into Telegram allows victims to increase their trust in the phishing service. In one scenario, the user is asked to vote through authorization using a messenger, after which the attackers try to gain access to the session. Another option is related to cryptocurrencies: the victim is persuaded to connect it to receive a bonus or check the balance, and then sign the transaction.
Mikhail Shurygin, Chairman of the ROCIT Commission on cloud technologies, hosting and information security, noted that opening a message by itself does not allow malware to debit funds. The user must additionally be persuaded to connect the wallet and confirm the transaction. The expert called fake games and practical jokes, fake airdrops and investment cabinets the most likely schemes. Scammers may also offer to install an alleged update or additional application.
"The main danger is that the fraudulent service visually becomes part of the messenger," he said.
The problem is also relevant for the corporate sector. iTprotect information security specialist Alexey Bespoyasko recommends combining employee training with mail and web traffic filtering, sandboxes, professional systems (EDR/XDR) and multi-factor authentication.
Thus, the key risk of the new messenger features is not that any interactive message automatically infects the device, but that it becomes easier for fraudsters to pass off a malicious service as part of the service itself. Experts recommend launching Mini Apps only from verified sources, not linking crypto wallets and cards to unfamiliar services, and not trusting promises of easy earnings.
Переведено сервисом «Яндекс Переводчик»