Telegram Phishing at Scale — 9,814 Domains Sharing One Links Fingerprint
ID: a53221d6-1da4-4e6b-9711-788f2201c8d7
STIX ID: report--a53221d6-1da4-4e6b-9711-788f2201c8d7
Threat Score
72/100
Webamon Research discovered a large Telegram phishing cluster of 9,814 domains that all share a single outbound-links fingerprint, active from 20 Sep 2025 to 6 Jun 2026. The campaign uses DGA-style short randomized domains under cheap TLDs, resolves to only two ASNs (Cloudflare and Telegram Messenger Inc), produced 17,593 scans (10,000 analyzed) with peaks in January 2026, and is designed for large-scale credential theft; the consistent template and ASN concentration point to a single operator and provide actionable pivots for hunting and takedown.
