Report: Hackers utilize Telegram bot for conducting large-scale phishing scams

Security researcher Radek Jizba, from ESETResearch, has uncovered a highly sophisticated tool known as Telekopye, which enables criminals to create convincing phishing websites, emails, SMS messages, and more.

Operating under the code name Neanderthals, a group of threat actors have been able to present themselves as a legitimate company in order to function within a structured framework. Aspiring members are recruited through underground forums and are granted access to specific Telegram channels, where they can communicate with other members and monitor ongoing operations.

The Neanderthals’ ultimate goal is to commit one of three types of scams — seller, buyer, or refund. Seller scams involve duping unsuspecting victims into buying nonexistent items, while buyer scams involve impersonating buyers in order to trick merchants into disclosing financial information. Refund scams occur when Neanderthals mislead victims into believing they are offering a refund only to deduct the same amount of money again.

In order to carry out these scams successfully, the Neanderthals use a variety of strategies. For example, when attempting a seller scam, they prepare additional photos of the non-existent item in case the victims request more information, and manipulate internet images to make reverse image searches more difficult. Buyer scams require careful planning and research, as the Neanderthals choose targets based on factors such as gender, age, experience in online marketplaces, ratings, reviews, completed trades, and the type of items they sell, in order to tailor their approach and increase the chances of success.

To entice victims, the Neanderthals also engage in real estate fraud, creating fictitious apartment listings. They remain anonymous by using VPNs, proxies, and TOR, making it difficult for authorities to track them down. These revelations have brought to light the advanced tactics used by cybercriminals and serve as a reminder for individuals and businesses to remain vigilant against such sophisticated scams.