Hunting Phishing Infrastructure on Netlify: Telegram Bot Exfiltration Across Multiple Lure Themes
ID: e15af37f-47fb-4f8d-b319-db99a58c5334
STIX ID: report--e15af37f-47fb-4f8d-b319-db99a58c5334
Threat Score
65/100
This report documents a 21-day phishing campaign (Apr 5–25, 2026) abusing Netlify subdomains and Telegram Bot API for exfiltration across multiple lure themes (social media, enterprise auth, webmail, gaming). The researcher pivoted on Webamon signals (dom:"api.telegram.org") to identify 120 active pages, detailed TTPs (camera hijack, credential harvest, IP/browser fingerprinting, redirect to secondary stages), and provided IOCs (malicious netlify.app hosts, Telegram chat IDs, DigitalOcean Spaces URL, api.ipify.org) and mitigation recommendations (block/inspect outbound api.telegram.org from browser contexts and treat unknown *.netlify.app as dynamic-content risk).
