Alerts & Notice|Last Updated04/07/2026

Security Alert: Telegram "Session-Grabber" Phishing Adds Fake "Microsoft Teams" Meetings — and Leaves a Traceable Device Fingerprint

Publish Date: Saturday, 04 July 2026, 10:14 AM UTC

Following our 10 June 2026 alert on the real-time Telegram/WhatsApp "session-grabber" campaign targeting Iranian journalists and civil-society figures, CERTFA has confirmed the operation is active and evolving. The operator now lures targets with a counterfeit "Microsoft Teams" online meeting — delivered over WhatsApp/Telegram from an impersonated known contact, sometimes reinforced with an AI-cloned voice note — and hosts each lure on a disposable Cloudflare Quick Tunnel (hxxps[:]//<random-words>[.]trycloudflare[.]com) or on the same homoglyph domain teiegram[.]site (a look-alike of "telegram" using a capital I in place of the lowercase l, so it renders as "telegram" while remaining pure ASCII with no browser warning). The core mechanism is unchanged and unchanged-ly dangerous: the "meeting" page never connects to a real service — when the target clicks to join, the operator's server begins a genuine Telegram login as the victim, Telegram sends the real one-time code to the victim's own device, and the victim types that code (and, if prompted, their two-step-verification password) into the fake page, handing the operator a live, portable session that defeats SMS- and app-based one-time codes. This update reports two new findings: a second confirmed victim in the Iranian diaspora, and — most useful for the community — the exact device fingerprint the operator's client leaves behind in a hijacked account's Active Sessions list, which anyone can check for themselves.

Phishing Kit Analysis

Hosting & Origin: Each victim is worked through a short-lived per-victim endpoint — a Cloudflare Quick Tunnel (*[.]trycloudflare[.]com) or a teiegram[.]site subdomain (my[.]private[.]microsoft-teams[.]) — that is toggled live only while a target is engaged and torn down afterward. Behind Cloudflare, the real origin has been de-cloaked to a single dedicated server, 84[.]200[.]24[.]161, physically hosted in a Frankfurt, Germany datacenter (firstcolo / Accelerated IT Services). The hosting provider (Ultahost, AS214036) is a US-registered, multi-country reseller — so "Germany" is the box's physical location, not an attribution signal in itself.

Lure Page: A "Microsoft Teams" / online-meeting waiting room ("Please wait, the meeting host will let you in soon") that transitions into a Telegram-styled prompt for a "meeting code." The requested code is the victim's real Telegram login code; a follow-up screen harvests the two-step-verification password; and a fake "syncing" / "private dashboard" screen (seeded with opposition-media channels) masks the takeover in progress.

Backend Endpoints: The relay logic is entirely server-side — the victim's browser only ever communicates with the lure host, so telegram.org never appears in the page's network traffic. The backend is a Python (FastAPI / uvicorn) application; its exposed API specification is literally titled "Microsoft Teams" (SHA-256 3b12558fba8cf75d464756f75960192acd54d4a2ed9d0a59c3b63b53884e81ae), tying the origin server directly to the fake-Teams theme.

Attacker Device Fingerprint (new): When the operator logs in as the victim, Telegram records the operator's client in the victim's Settings → Devices / Active Sessions and dispatches a genuine "new login" security notification. In a confirmed case, that session read:

Device: teltoone, 1.0, MS Teams, Android, V8 Core — Location: Germany

Decoded against Telegram's published client-identification fields (the authorization object populated at login via initConnection), this is device model teltooneapp version 1.0app name MS Teams (the operator registered their Telegram API application under a Microsoft-Teams cover name — a server-side value, not something the victim controls), platform Android, and system version V8 Core. No genuine Telegram Android app reports this combination: the placeholder 1.0 app version and the V8 Core label (V8 is the JavaScript engine behind Node.js/Chromium) indicate an automated, non-native client identifying itself as "Android" — consistent with a JavaScript-based Telegram library performing the login relay, rather than a real phone. This fingerprint is a community self-check: any Iranian diaspora user who finds this device in their Active Sessions should treat the account as compromised (see Recommendations). It is a high-value candidate signature observed in a single confirmed case and absent from prior public reporting — use it for detection and correlation, not as standalone proof of a specific actor.

Post-Takeover Behavior: The operator has been reported to delete Telegram's "new login" security alert from the compromised account to conceal the intrusion, retains covert access to message history, contacts and groups, can read incoming codes, and can impersonate the victim to their contacts for onward spear-phishing — placing the victim's entire network at secondary risk.

Malicious Behaviors (MITRE ATT&CK):

TechniqueIDDescription
Spearphishing via ServiceT1566.003Lure delivered over Telegram/WhatsApp from an impersonated trusted contact.
ImpersonationT1656Operator poses as a known editor/producer, including AI-cloned voice notes.
Phishing for InformationT1598Fake "Microsoft Teams" meeting page elicits the login code and 2FA password.
Multi-Factor Authentication InterceptionT1111Real-time relay of the victim's genuine Telegram one-time login code.
Steal Application Access TokenT1539Captured login yields a portable Telegram session (full account takeover).
Internal SpearphishingT1534Hijacked account used to target the victim's contacts.
Indicator Removal on HostT1070Telegram "new login" security alert reportedly deleted post-takeover.

Social Engineering & Delivery Analysis

The approach is personal and patient. The operator contacts the target as a familiar person — often a real, impersonated editor or producer — sometimes from a new phone number ("it's my new number"), and proposes an urgent interview, consultation, or team "meeting," then supplies the link. To overcome hesitation, the operator has sent AI-generated voice notes imitating the trusted contact's voice. Representative lure messaging (translated from Persian; personal names redacted):

  • "…wherever you are, may you be safe. We have a project we're working on — I wanted to see if you have time to consult and collaborate with the team." (Translated, representative)
  • "…do you have time now for a quick talk? Let me tell the team to get ready — to see you and do the meeting. I promise I won't take much of your time." (Translated, representative)
  • "Did you join? Wait a moment — the team is coming, they're on air now." (Translated, representative, spoken while steering the target into the fake meeting page)

Assume a voice note is not proof of identity. The "meeting code" and any "account unlock" password requested on the page are the victim's live Telegram login code and 2FA password.

Attribution Indicators

Consistent with our June assessment, CERTFA weighs the following and deliberately does not over-narrow:

  • Victimology: Exclusive targeting of Iranian opposition/diaspora journalists and activists — including a newly confirmed second diaspora victim — with no financial-crime motive.
  • Tooling / kit family: A bespoke Telegram login-code-relay + 2FA-harvesting session-grabber built on an open-source webcam-phishing "online meeting" template, with a Python (FastAPI) origin whose API is themed "Microsoft Teams."
  • Client fingerprint: The teltoone / MS Teams / V8 Core Active-Sessions signature indicates an automated, JavaScript-based relay client (the specific library cannot be confirmed from the string alone).
  • Delivery tradecraft: Impersonation-plus-meeting pretext, AI-cloned voice, disposable Cloudflare tunnels, and disciplined post-takeover cleanup — a mature, persistent-access-oriented operator.
  • Language: Native, colloquial Persian in the lure messaging and voice notes.
  • Corroboration: Consistent with independently documented Telegram-account-takeover activity against Iran International-adjacent figures.

Assessment: CERTFA continues to assess, with moderate-to-high confidence, that this operation most likely belongs to the MOIS cluster tracked as Banished Kitten (also Storm-0842 / "Dune"), on the basis of the kit family and victimology. An IRGC-linked cluster (APT42 / Charming Kitten) is retained as a less-likely alternative. Critically, the new evidence in this update — the device fingerprint, the German hosting geo, and the second victim — is consistent with this assessment but does not independently discriminate between the Iranian clusters, and it does not narrow attribution further. This attribution remains tradecraft- and victimology-based, not a confirmed infrastructure overlap; there is no shared infrastructure, kit hash, or certificate tying this specific operation to either cluster.

Indicators of Compromise (IOCs)

Defanged. Verified 4 July 2026. The backend is on-demand and mutable — re-verify before enforcement. A machine-readable CSV is available to vetted partners.

Domains & Hosts

TypeValueDescription
Domainteiegram[.]siteHomoglyph lure domain (capital I for l); Cloudflare-fronted apex.
Hostmicrosoft-teams[.]teiegram[.]siteFake "Microsoft Teams" meeting lure host.
Hostmy[.]teiegram[.]sitePer-victim lure subdomain (staged/toggled).
Hostprivate[.]teiegram[.]sitePer-victim lure subdomain (staged/toggled).

Origin Infrastructure

TypeValueDescription
IPv484[.]200[.]24[.]161De-cloaked origin (dedicated host, Frankfurt/DE). Block this single host only.
Range84[.]200[.]24[.]0/24Shared reseller range — do NOT blunt-block (≈254 unrelated tenants); hunt-only.
Hash3b12558fba8cf75d464756f75960192acd54d4a2ed9d0a59c3b63b53884e81aeSHA-256 of the backend OpenAPI spec titled "Microsoft Teams".

Attacker Telegram Session Fingerprint (check your own Active Sessions)

TypeValueDescription
Device stringteltoone, 1.0, MS Teams, Android, V8 CoreOperator's client in a hijacked account's Active Sessions. Candidate signature (single confirmed case).
Tokensteltoone · MS Teams · V8 CoreFor correlation/hunting only. "MS Teams" / "Microsoft Teams" must NOT be used as a blunt content filter — it collides with legitimate Teams traffic.

Delivery / Contact Indicators

TypeValueDescription
URL patternhxxps[:]//<random-words>[.]trycloudflare[.]comDisposable per-victim Cloudflare Quick Tunnels; ephemeral, torn down after use.
TradecraftImpersonated known contact + AI-cloned voice note, often from a new numberSocial-engineering delivery vector.

Related but SEPARATE Operation

To avoid over-attribution: the IP 194[.]76[.]226[.]226 (AS39378, servinga GmbH) hosts a different Iranian-nexus Telegram-phishing operator documented elsewhere. It is also in Frankfurt/Germany — which is precisely why a country-level "Germany" geolocation cannot distinguish the two. Do not conflate this address, or the German hosting geo, with the operation described above.

Recommendations

  • Never enter a Telegram or WhatsApp login code on any website. Telegram never asks for your login code on a web page, and no genuine meeting requires it — treat the code like a recovery key and never type it anywhere reached from a message.
  • Verify a "known contact" who reaches you from a new number via a second channel before acting, and treat voice notes as potentially AI-cloned — not proof of identity.
  • Set a two-step-verification password in Telegram (Settings → Privacy & Security → Two-Step Verification) if you have not already.
  • Check Settings → Devices / Active Sessions now. If you see an unfamiliar session — especially one matching teltoone / MS Teams / V8 Core — screenshot it (to preserve evidence), then terminate it, change your password and 2FA, and warn your contacts that your account may have been used to message them.
  • If you believe you were targeted or compromised, contact CERTFA.