Scammers have begun actively using news surrounding Telegram and Pavel Durov (included in the list of terrorists and extremists in Russia) to spread new phishing schemes related to the Gram cryptocurrency. Users are offered to urgently exchange old tokens, withdraw funds before the alleged upcoming messenger block, or receive free cryptocurrency through special services. According to experts, criminals create fake websites and Telegram bots, designed in the platform's official style. The main tools of influence are the fear of losing funds and promises of easy earnings.
Fake Telegram Services
Following the emergence of news surrounding Telegram, cybersecurity specialists recorded a sharp increase in suspicious activity. According to them, malicious actors began mass-registering domains mentioning Telegram, Pavel Durov, and the Gram cryptocurrency — the native token of the TON blockchain — as well as launching fake services promising users to preserve access to their assets or quickly earn money on the new "coin".
— After July 30th, SBA analysts have recorded increased registration activity around Telegram. Over six days, the number of new domains mentioning Telegram or Durov grew by approximately 18%. At the same time, the number of domains with potential signs of phishing doubled. The batch registration of 11 similar domains at once on August 3rd, masquerading as Telegram verification and protection services, is particularly noticeable, — Sergey Trukhachev, head of the Smart Business Alert service at ESA PRO, told Izvestia.
According to him, scammers actively exploit user concerns related to Telegram's future. People are convinced that services affiliated with the messenger's founder will supposedly soon become unavailable, so it is necessary to transfer funds or use a new crypto service as quickly as possible.
Criminals practically immediately began using the news hook to create new storylines, noted Pavel Kovalenko, director of the fraud counteraction center at Informzashchita. According to him, the launch of the built-in non-custodial Gram wallet opened additional opportunities for malicious actors. Users have not yet had time to understand the new function, which scammers actively exploit by passing off fake services as official Telegram tools.
A similar assessment was given by Fedor Chunizhekov, head of the research group at Positive Technologies. He noted that high-profile events traditionally become the basis for new social engineering scenarios.
— The user is told that it is necessary to "urgently confirm the account," "withdraw assets before the block," "exchange old coins," "get free tokens," or "register in the new service before others." Precisely the feeling of urgency, the promise of free benefit, and the exclusivity of the offer become the main tools of manipulation and psychological pressure, — he explained.
Systemic Approaches of Scammers
The main task of scammers is to convince a person to voluntarily provide access to their crypto wallet. After clicking the link, the user is asked to authorize via Telegram, enter a seed phrase, or confirm a transaction, after which the assets are irrevocably transferred to the criminals, Pavel Kovalenko explained.
In essence, criminals bet not on hacking technologies, but on psychological pressure, added Igor Bederov, chairman of the Council on Countering Technological Offenses of the NSB KS of Russia, founder of Internet-Rozysk.
— Scammers don't hack complex blockchain protocols; they hack gullibility and the craving for 'freebies' against the backdrop of panic headlines. Moreover, the number of registrations for phishing domains with words like gram, wallet, convert, and gift in conjunction with Telegram has increased dozens of times, — the expert emphasized.
At the same time, fraudulent campaigns are becoming increasingly complex. Today, malicious actors build entire trust chains, sequentially moving the user from search results to a Telegram channel, then to a bot, and onto a fake website, said Mikhail Shurygin, chairman of the ROCIT commission on cloud technologies, hosting, and information security.
— We can speak of a transition from primitive distribution of malicious links to creating entire "ecosystems of false trust," — he noted.
Quality design, the presence of reviews, support services, and even a secure connection are no longer considered signs of a resource's reliability. It is important for users to remember that Telegram and its official services do not conduct cryptocurrency giveaways or token conversions through third-party websites or bots, the expert reminded.
Malicious actors also actively use phishing pages and cryptodrainers — malicious programs that prompt users to independently connect crypto wallets to fake sites or enter Telegram login credentials under the pretext of receiving free tokens and other bonuses, added Maria Sinitsyna, senior analyst of the digital risk protection department at F6 company.
— The main vulnerability in 99% of such attacks lies at the intersection of technology and human psychology, — noted Igor Bederov.
The interviewed experts agree that the main protection for digital assets remains caution. They recommend not clicking on advertising links, not entering seed phrases and confirmation codes on third-party resources, and using only official Telegram services when working with crypto wallets.
end-content





