Fraudsters are giving away a Telegram Premium subscription

marry 29.11.2024, 09:00 AM

The average person spends $938 a year on 12 subscriptions, a recent Kaspersky study found. There are subscriptions for everything: music, movies, fitness, anti-virus software, and even messaging apps, which only goes to say that subscriptions have become a part of our daily lives and a common expense we agree to in order to use certain services.

Users of the popular application Telegram also have the option of paying for a subscription to Telegram Premium, which removes all the limitations of the free version of the messenger. And the best thing about it is that you can gift it to your friends. If you have a large list of contacts, Telegram often reminds you of this possibility.

Kaspersky has warned against fraudsters abusing the Telegram Premium subscription to steal user data. Fraudsters take advantage of the fact that the subscription to Telegram Premium can be given as a gift, so they offer it to the users of the application. However, what is behind these gift subscriptions from cybercriminals and how can you protect your Telegram account?

It all starts with an innocent-looking Telegram message from someone in your contact list: “A gift has been sent to you – a subscription to Telegram Premium”. The message contains a link that at first glance seems legitimate and as if it really leads to the official Telegram Premium channel. But there is a problem. The text you see – – actually hides a link to a completely different site, a phishing site. The page looks like a regular Telegram login page in a web browser. However, the scam is revealed by the URL: the address starts with something familiar but has something extra, which would not be there if it were a legitimate page.

If you enter your account details here, consider them stolen. Your username, password, and possibly your two-factor authentication code will end up in the hands of fraudsters. Once you submit your information, the scammers display a congratulatory message and start a 24-hour timer, claiming it’s the activation period for Telegram Premium. This delay is a classic cybercrime tactic. Fraudsters count on the fact that the user will either forget about the subscription or will believe that he is really on his way. The only thing that will most likely happen during these 24 hours is that you will permanently lose access to your account.

Since Telegram Premium was launched a few years ago, various scam scenarios have appeared.

For example, cybercriminals claimed to be the organizers of a free raffle for a three-month subscription to Telegram Premium. However, there is no real winner draw – everyone is a winner. But instead of a reward, victims are directed to click on a link and log into Telegram on a phishing site. And that’s where their accounts were compromised.

Another common tactic is distributing APK files for allegedly “hacked” Telegram apps bundled with Premium subscriptions. Such modified applications are often nothing more than malware in disguise.

These scammers operate all over the world, and if this scam hasn’t reached your region yet, rest assured that it will soon.

How to protect your Telegram account?

Always remember that there is no such thing as a free lunch. Before you get excited about a surprise gift, check if the sender really has good intentions. Contact him through another communication channel – call him or use another messenger.

Buy subscriptions only through official channels.

Enable two-factor authentication. This could be your last line of defense in case you fall for a scam.

Learn about other ways scammers can steal your Telegram account. There are countless schemes, and many are more sophisticated than they appear.

Slow down, even if you’re in a hurry. Scammers like to pressure victims with timers. When it comes to your safety, ignore the countdown and take your time.

Be careful with alternative versions of apps. Use only official applications, as unofficial versions almost always come bundled with Trojans.

Source: www.informacija.rs