Phishing campaign used Telegram API to create malicious domains that bypassed secure email gateways. Phishing emails appeared to come from an internal source, but actually originated with a source outside the organization, Cofense says. The targets of these malicious emails mainly worked in the U.K. financial services sector. The attack appeared active in mid-December 2020 and has since stopped, researchers say. The phishing emails typically come with an urgent message alert in the subject line, such as “Review All Pending Messages””]
Source: https://www.govinfosecurity.com/fraudsters-using-telegram-api-to-harvest-credentials-a-16040