AntiMalwareSeptember 2, 2026🇷🇺Translated from Russian

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Scammers are now hiding phishing pages inside Telegram by leveraging its built-in Mini Apps and WebView mode. After the messenger's update on August 25, attackers can disguise fraudulent sites as games, polls, giveaways, or banking interfaces that appear native to the application.

Users encounter familiar buttons and clean windows that prompt them to confirm transfers, claim bonuses, or participate in votes. Instead of receiving rewards, victims may hand over account credentials, connect cryptocurrency wallets, or approve malicious transactions. In voting schemes, targets are asked to provide phone numbers and confirmation codes under the pretext of preventing vote manipulation, enabling account takeovers.

Cryptocurrency lures often involve fake airdrops or balance checks that require connecting a wallet to an unknown service. Another technique mirrors the ClickFix method: the app reports an error, copies a command to the clipboard, and instructs the user to paste it into PowerShell. Because the victim performs the harmful action manually, traditional antivirus solutions may not detect the activity.

Opening a message or Mini App alone does not automatically steal funds. Attackers must still convince the target to authorize access, enter codes, install software, or confirm operations. Social engineering remains the primary tool rather than any automated exploit.

Security researchers recommend launching Telegram Mini Apps only from verified sources, avoiding entry of verification codes in polls, and never connecting payment cards or crypto wallets for questionable promotions.

Related articles

AntiMalwareFraud & Social Engineering

Google Introduces Multi-Step Verification for Android APK Sideloading to Combat Fraud

Google has begun rolling out an enhanced installation flow for Android apps installed outside of Google Play. Users must first confirm that no one is coercing them to enable unknown sources, then reboot their device and wait 24 hours before the option becomes available. The new process includes explicit warnings about scammers who pressure victims into enabling sideloading, noting that legitimate organizations never require this setting. After the waiting period, users can grant the permission for seven days or indefinitely. The change does not affect ADB installations, preserving a workaround for advanced users. Google states the delay is intended to give people time to reconsider before enabling potentially risky settings. An Android Authority poll showed 88 percent of respondents expect further restrictions in the future.

HabrFraud & Social Engineering

Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks

A cybersecurity expert with years of SOC and pentest experience explains why traditional awareness training fails against social engineering. The article details how attackers exploit psychological levers such as authority, urgency, reciprocity, social proof, and emotion to bypass conscious decision-making. It emphasizes that people who fall for attacks are often the most helpful and diligent employees, not the careless ones. Instead of relying on willpower in stressful moments, organizations must implement procedures that enforce independent verification and protect the right to pause. The piece also highlights how a blame-free culture dramatically reduces incident impact by encouraging early reporting. Technical measures that reduce reliance on a single human decision are presented as effective supplements to policy.

AntiMalwareFraud & Social Engineering

Scammers Impersonate Gas Workers to Pressure Russians into Overpriced Repairs Before September 1 Deadline

Fraudsters have started visiting apartments and private homes in Russia, posing as employees of gas services or management companies. They claim to have discovered critical issues such as gas leaks, faulty valves, problematic meters, or dangerous chimneys during supposed August inspections. Residents are warned that gas will be disconnected by September 1 unless immediate and expensive repairs are paid for on the spot. In some cases, scammers demand prepayments for urgent work and then disappear with the money. Victims are often charged 5 to 10 times the market price for equipment replacement. The Moshelovka platform of the Narodny Front has reported these incidents and issued safety recommendations. Residents are advised to verify maintenance schedules in advance and never pay cash or transfer money to individuals without confirmation.

HabrFraud & Social Engineering

VC.ru Blocks Lawyer's Account After Article Exposing In-Platform Phishing Scheme

A Russian lawyer specializing in IT law and cryptocurrency regulation published an article on VC.ru detailing a phishing operation that abused the platform's own articles. The scheme involved posting seemingly legitimate content that later had links altered to redirect users to fake services stealing crypto assets. Within an hour of publication, the author's four-year-old account was automatically blocked under rules prohibiting multiple accounts to evade bans, despite the author having no prior restrictions or secondary accounts. After formal complaints citing Russian data protection law 152-FZ and consumer protection statutes, the platform reversed the ban but initially reclassified the account as commercial, demanding a monthly fee of 56,000 rubles for indexing. The account status was later restored following further legal correspondence. The incident highlights platform moderation challenges when reporting security threats involving paid accounts on the same site.