Help a friend scam on Telegram
- 16 min read - Text OnlyA new scam is going around on Telegram! One that preys on your friends and then you. It is in fact, a worm. An automated attack that takes over your account with the objective to spread and take over more accounts.
What if you are impacted?
To get someone to help, you need to be an extremely clear and consise communicator. Stick to the bare essentials, give enough evidence for them to act and help you.
Here's what you need to do:
- Send an email to
recover@telegram.org
- Also prepare the same message to go into Telegram Support.
- From an email from a common service like gmail or outlook
- Clearly identify the following:
- Your phone number
- Your username
- The date and time you lost access, including a time zone like "US Central"
- What app you normally use
- Your IP address, which you can find on What is my IP address.
- Patiently and respectfully state that you have lost your account to phishing scam.
- Then mention a friend, who was compromised, messaged you to help them. It involved a bot. That bot showed a button saying: "Help a friend to unblock".
- Continue to state that the bot had the name "Telegram" and used the telegram logo. This bot was impersonating Telegram to you.
- Lastly, state that clicking the button opened a window with a telegram form asking for a phone number.
- Because this form opened up in the telegram app, had a telegram logo, had a bot named "Telegram", you were convinced it was really Telegram. You fell for the phishing scam.
- Ask for your account to be restored to you, your original phone number, and to prevent bots like this in the future.
- If you have a two-step password, do not state your two-step password to them. This is something only the Telegram app on your phone or desktop should receive in its normal log-in flow and periodic "Are you sure you remember?" prompts.
I had my account disabled at one point, in fact, while I was out camping! While I did not fall victim to a phishing scam, I was banned because I first used a Voice-over-IP number, one I owned for 10 years. Unfortunately, most bot accounts, scammers, and so on use voice-over-ip numbers.
Following the above, hopefully you will get your account back within a week.
How they phish you
Your friend's account got taken over. They message you asking for help. They might even ask for you to pay for premium to get them unlocked. As an alternative, they say you can help by using an official telegram bot.
They send you a bot account that looks like @XYZ_TelegramBot
.
It has the buttons:
- Help a friend unblock
- Receive membership for free
- Apply to protect my account
- Detect account abnormality
All buttons do the same thing. It does not matter which button you click. They all open the same in-app web view.
Everything here sets up the victim to believe the threat actor is legitimate. There is no identification that this is not an official telegram bot. The Telegram brand is impersonated on Telegram's own platform, and Telegram's own words set expectations for the victim that they will interact with a web view, an out of bounds experience.
Upon accepting the disclaimer that your IP address may be revealed, the web app opens and shows a familiar login screen. Effective threat actors clone and copy what is familiar. The less surprising the phishing scam is, the easier you will fall victim to it.
Compare this scam to the legitimate web.telegram.org
web client:
There are differences. Are there enough that you, while tired, stressed, wanting to help a friend, would notice them and back out?
The login flow continues. You will be tricked in relaying a one time pass code.
Two-Step verification helps you keep your account when your phone number is taken from you.
In this case, the threat actor can simply ask you for your password next.
Next, the threat actor disconnects all other sessions from your account. You are then locked out! You are closed off and unable to see or message your friends!
Then, they change your phone number or your two-step password. Yes, they can do that, and so can you.
Then the account is put into a queue for a human, likely one who receives pennies for participating in this crime, to contact your friends and capture their accounts too.
What can you do if your friend is compromised?
Mute and Archive their chat. Contact them through other known means. Share this article with them so they can recover their account too!
If they sent you a bot account like @XYZ_TelegramBot
, open the bot profile. You do not need to hit /start
, though if you do, no harm has been done.
- Click or tap on Report.
- Click or tap on Fake Account.
- Enter a message like:
This account is scamming user accounts. It is pretending to be an official Telegram account. Please search for and remove accounts with TelegramBot in their username.
- Submit.
If you've done your part, guess what? Telegram actually will ban the account!
You too can combat this problem and help prevent your friends from being phished.
Please share this article to your friends.
After all. Scammers do not need to read your roleplays. Wink wink.
Advice for Telegram
Not that I expect them to even read my article... Here are my recommendations for any platform with public integrations to protect their users. Google has protections like these in place. Telegram needs to step up if they want to be the WeChat of the western world.
- Revoke all bot accounts ending in "
TelegramBot
". - Investigate and remove accounts that have created bots created with such user names.
- Further investigate if the accounts that have created those bots were themselves compromised before creating such bot accounts.
- Prevent registration of all bot accounts that contain "
Telegram
". - Employ some form of image recognition to prevent the use of the Telegram logo on bot account profiles.
- Add extra scrutiny to in-app web features.
- Adjust the message presented to the user that they are exiting Telegram and that the application and views do not represent Telegram.
- Reconsider the comingled experience of official telegram bots, support accounts, and so on, from user contributed bots and user accounts.
- Consider other security, two factor, or account recovery mechanisms and their security risks and mitigations.
- Improve education on verification labels for official bots.
Last words
For those affected, I am truly sorry you are going through this. Please try out the recovery method mentioned above and share this elsewhere. You may lose access to your chat histories. You may have some personal information in your private saved messages stolen.
I highly recommend you change passwords elsewhere, just in case you ever pasted it into telegram to copy between devices.
May the naga be with you.
More information!
Update - July 9th, 2023
Unfoxo tried this out with a sacrificial account. Here's what he recorded:
Upon entering your phone number, it will present an emoji and "Enter Captcha"
You will then get a message from telegram with your one time passcode.
Next, you will see a message from telegram saying there is a new login. It will come from your IP address, it will come from your device type, and it uses "Telegram WebK", which is a real client.
A few seconds later, while you are reviewing an odd message, Telegram will send another one time passcode! Except in the background, it sends this passcode to the threat actor to get into your account!
The next thing you know, someone connects into your account from Hong Kong, of all places.
Sometimes, Telegram will block these attempts.
What's interesting here is that the official Telegram bots all have twitter style verified labels next to them.
Meanwhile, their own do not have such labels.
I have also heard, from one unfortunate soul, that their phone number has stayed the same, but every time they connect they are automatically booted out of their account. From this information, I suppose that the threats do not have numbers to switch the accounts to and are automating account retention.