Phishing Scammers Leverage Telegraph’s Loose Governance to Host Crypto and Credential Scams

Stu Sjouwerman | Jun 23, 2022

Phishing Scammers Leverage GovernanceThe free and unmonitored webpage publishing platform has been identified as being used in phishing scams dating back as early as mid-2019, as a key part to bypass security solutions.

By and large, Telegra.ph is a legitimate platform. In the simplest of ways, it supports the creation of a basic webpage – complete with hyperlinks and images – in a matter of seconds. According to security researchers at email protection vendor Inky, a pattern of use of the platform has been seen, including a recent uptick.

Scammers send out phishing emails that contain a link as the call to action that lead to a telegra.ph webpage.

Telegraph

Source: Inky

This legitimate use of a platform like telegra.ph has allowed some of these scams to pass through security scans. Once on the web page, victims are prompted to click embedded links. In the case of credential attacks, it leads to an impersonated Microsoft 365 logon page. And in the case of crypto scams, the page points victims to various ways they can pay in crypto to fend off a faux extortion they believe to be real.

The clincher here is that a simple realization of the use of a domain that has zero to do with the actual email would put these attacks to rest before they can do any harm. It’s through Security Awareness Training that users of organizations can see these scams for what they are, and avoid engaging them entirely.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.