{"id":24520,"date":"2025-08-13T07:19:51","date_gmt":"2025-08-13T11:19:51","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/?p=24520"},"modified":"2025-08-20T16:25:28","modified_gmt":"2025-08-20T12:25:28","slug":"phishing-and-scam-in-telegram-2025","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/24520\/","title":{"rendered":"Telegram scams with bots, gifts, and crypto"},"content":{"rendered":"<p>Remember the early days of the internet and <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-protect-against-spam\/52974\/\" target=\"_blank\" rel=\"noopener nofollow\">419 (aka \u201cNigerian prince\u201d) scams<\/a> promising mountains of gold just for you?\u00a0That era is thankfully over, but today a new curse is all the rage: messenger phishing. Due to its vast user base, the openness of its API, and support for crypto payments, one particular messenger \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/tag\/telegram\/\" target=\"_blank\" rel=\"noopener nofollow\">Telegram<\/a> \u2014 has become a very popular choice for phishing cybercriminals. So what new tricks do Telegram scammers employ, and how can you spot them in time?\n<\/p>\n<h2>Telegram bots in the service of cybercriminals<\/h2>\n<p>\nTelegram is home to a huge array of bot-related scams. And sometimes attackers offer their bots to other bad guys to create new ones. If you\u2019re feeling a bit overwhelmed, don\u2019t worry: our <a href=\"https:\/\/securelist.com\/telegram-phishing-services\/109383\/#automated-phishing-with-telegram-bots\" target=\"_blank\" rel=\"noopener\">Securelist blogpost<\/a> takes a detailed look at this phenomenon \u2014 known as phishing-as-a-service.<\/p>\n<p>Attackers often use Telegram bots instead of websites. It\u2019s much easier to lure potential victims this way; it\u2019s far harder to create and maintain a full-fledged phishing site and get victims to swallow the bait. With bots, everything\u2019s simpler since users don\u2019t need to leave Telegram, which many mistakenly think is a safe environment by default.<\/p>\n<p>So what does it look like in practice? One example is a new scam involving cryptocurrency investments: <em>\u201cWe\u2019re handing out a new token to everyone\u00a0\u2014 just enter the bot and go through KYC verification\u201d. <\/em>Of course, \u201cKYC verification\u201d for scammers doesn\u2019t mean a passport photo or a video call to confirm your identity, but depositing a sum of cryptocurrency. And, yes, this crypto goes straight into the attackers\u2019 account, while you get zilch.<\/p>\n<div id=\"attachment_54095\" style=\"width: 636px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153519\/phishing-and-scam-in-telegram-2025-01-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-54095\" class=\"size-full wp-image-54095\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153519\/phishing-and-scam-in-telegram-2025-01-1.jpg\" alt=\"Telegram bot offers fake KYC verification \" width=\"626\" height=\"959\"><\/a><p id=\"caption-attachment-54095\" class=\"wp-caption-text\">Telegram bot offers fake KYC verification<\/p><\/div>\n<p>Sure, Telegram bots aren\u2019t limited to extracting crypto. For instance, we uncovered a scam inviting victims to get paid for watching short videos. Where? In a Telegram bot, of course.<\/p>\n<div id=\"attachment_54098\" style=\"width: 747px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153521\/phishing-and-scam-in-telegram-2025-02-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-54098\" class=\"size-full wp-image-54098\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153521\/phishing-and-scam-in-telegram-2025-02-1.jpg\" alt='Victims \"earn\" two euros per video view' width=\"737\" height=\"623\"><\/a><p id=\"caption-attachment-54098\" class=\"wp-caption-text\">Victims \u201cearn\u201d two euros per video view<\/p><\/div>\n<p>Telegram bots are highly intrusive\u00a0\u2014 if you don\u2019t block them, they\u2019ll keep knocking on your door. Most phishing sites don\u2019t do this; user interaction with them plays out differently: visit the site, browse, leave. But chat with a Telegram bot just once, and it\u2019ll bombard you with suspicious links or pester you for access to manage your channels and groups. If you grow tired of an intrusive bot, just block it: open a dialog with the bot, tap its name, then select <strong>Block<\/strong>. That done, the pesky bot will message you no more.<\/p>\n<p>In another nasty bot-related scam, attackers persuade victims to start bot chats, then share their data or send money. Once the victim is hooked, the scammers rename the bot Telegram Wallet or Support Bot (mimicking supposedly official channels), transfer ownership of the bot to the victim\u2019s account without their knowledge, and report it to Telegram support. Thinking it was the victim who created the bot, Telegram support deletes not only the bot, but also the victim\u2019s account. The scammers do this to cover their tracks and muddy the waters for a possible police investigation.\n<\/p>\n<h2>Fake gifts and account theft<\/h2>\n<p>\nAttackers employ a variety of tricks to gain access to victims\u2019 accounts. One of the most common scams is a \u201cgift\u201d subscription to Telegram Premium. Check out our post <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-premium-scam\/52696\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>You\u2019ve been sent a \u201cgift\u201d \u2014 a Telegram Premium subscription<\/strong><\/a> for details. In brief: scammers message victims from the hacked account of a friend, prompting them to go to a phishing site to \u201cfinalize the subscription\u201d. There\u2019s no subscription, of course. Instead, victims have their own accounts stolen.<\/p>\n<p>Another new vector of fraud involves <a href=\"https:\/\/telegra.ph\/\" target=\"_blank\" rel=\"nofollow noopener\">Telegraph<\/a>, Telegram\u2019s tool for posting longer texts. Anyone can publish content there, and no prior registration is required, which is what attackers exploit since it\u2019s easy to redirect users to phishing pages. The result, as a rule, is one more hijacked account.<\/p>\n<div id=\"attachment_54099\" style=\"width: 878px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153523\/phishing-and-scam-in-telegram-2025-03.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-54099\" class=\"size-full wp-image-54099\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2025\/08\/13153523\/phishing-and-scam-in-telegram-2025-03.jpg\" alt=\"The user is lured into following the link to view the full version of the document \" width=\"868\" height=\"715\"><\/a><p id=\"caption-attachment-54099\" class=\"wp-caption-text\">The user is lured into following the link to view the full version of the document<\/p><\/div>\n<p>What else have scammers and phishers come up with? Threat actors are actively using AI to create deepfakes, steal biometric data, hide phishing attacks under temporary Blob URLs, and even spoof Google Translate subdomains. Read about these and other trends in <a href=\"https:\/\/securelist.com\/new-phishing-and-scam-trends-in-2025\/117217\/\" target=\"_blank\" rel=\"noopener\">our Securelist report<\/a>.\n<\/p>\n<h2>How to guard against Telegram scams and phishing<\/h2>\n<p>\nThe best tip is to apply critical thinking at all times. But even the smartest of us can sometimes act rashly, so try to read up on scams as much as possible so that your muscle memory automatically triggers the right response.\n<\/p>\n<ul>\n<li><strong>Don\u2019t follow links sent by people you barely know. <\/strong>Don\u2019t follow such links even if they promise a juicy gift, and never enter personal data on sites they point to.<\/li>\n<li><strong>Configure privacy and security in your Telegram account<\/strong>. See our <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-privacy-security\/38444\/\" target=\"_blank\" rel=\"noopener nofollow\">in-depth how-to<\/a> on two-factor authentication and secret chats.<\/li>\n<li><strong>Don\u2019t share one-time codes or passwords with anyone.<\/strong> And don\u2019t enter them anywhere except in the official Telegram app. Scammers know how to <a href=\"https:\/\/www.kaspersky.com\/blog\/when-two-factor-authentication-useless\/51434\/\" target=\"_blank\" rel=\"noopener nofollow\">trick users into revealing their OTPs<\/a>.<\/li>\n<li><strong>Use <a href=\"https:\/\/me-en.kaspersky.com\/premium?icid=me-en_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">reliable protection<\/a><\/strong>\u00a0that knows phishing when it sees it and warns you about it.<\/li>\n<li><strong>Block intrusive bots. <\/strong>As we said, they\u2019ll keep on knocking, so if after one chat with a Telegram bot you\u2019re sure that\u2019s enough, feel free to block it.<\/li>\n<li><strong>Set up automatic termination of all inactive Telegram sessions every week.<\/strong> In Telegram, go to <strong>Settings<\/strong>, then select <strong>Devices \u2192 Automatically terminate sessions \u2192 If inactive for \u2192 1 week.<\/strong><\/li>\n<\/ul>\n<p>\nIf your Telegram account is already hacked, read our post <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-account-hacked\/52775\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>What to do if your Telegram account is hacked<\/strong><\/a>. Time is of the essence \u2014 it\u2019s easier to restore access in the first 24 hours after an attack. And subscribe to <a href=\"https:\/\/t.me\/+hfDEDRUTiLJlOGE8\" target=\"_blank\" rel=\"noopener nofollow\">our Telegram channel<\/a>\u00a0for the inside track on new cybersecurity trends.\n<\/p>\n<blockquote><p>Other Telegram swindles:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-premium-scam\/52696\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>You\u2019ve been sent a \u201cgift\u201d \u2014 a Telegram Premium subscription<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-account-hacked\/52775\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>What to do if your Telegram account is hacked<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/toncoin-cryptocurrency-scam\/51042\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>\u201cBuy Toncoin and invite your friends\u201d: how scammers promise big earnings with cryptocurrency<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Everything you need to know about the latest Telegram scams and phishing, and how to stay safe.<\/p>\n","protected":false},"author":2710,"featured_media":24519,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1486],"tags":[1474,82,577,76,695,581],"class_list":{"0":"post-24520","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-accounts","9":"tag-hacking","10":"tag-messengers","11":"tag-phishing","12":"tag-scam","13":"tag-telegram"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/24520\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/phishing-and-scam-in-telegram-2025\/29402\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/phishing-and-scam-in-telegram-2025\/29348\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/28434\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/phishing-and-scam-in-telegram-2025\/31315\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/phishing-and-scam-in-telegram-2025\/40282\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/phishing-and-scam-in-telegram-2025\/13690\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/phishing-and-scam-in-telegram-2025\/54090\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/phishing-and-scam-in-telegram-2025\/23093\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/phishing-and-scam-in-telegram-2025-2\/24139\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/phishing-and-scam-in-telegram-2025\/32578\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/phishing-and-scam-in-telegram-2025\/29563\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/phishing-and-scam-in-telegram-2025\/35266\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/phishing-and-scam-in-telegram-2025\/34914\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/phishing\/","name":"phishing"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2710"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=24520"}],"version-history":[{"count":4,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24520\/revisions"}],"predecessor-version":[{"id":24574,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24520\/revisions\/24574"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/24519"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=24520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=24520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=24520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}