When planning a Telegram phishing simulation, follow these structured steps to ensure smooth execution and compliance:
Access your account on the TSAT platform.
Go to the Templates section and click on "Create Template".
Fill in the following fields:
Template Name: Assign a name for easy identification.
Category: Choose the appropriate category for the campaign.
Language: Set the language based on the audience.
Simulation Type: Select "Simulation Attack".
Attack Vector: Choose "Telegram".
Credential Harvesting:
Enable or disable the Credential Harvesting checkbox depending on whether the campaign will collect user credentials.
Add the Sender Phone Number (a valid number that can be used to send messages via Telegram).
The number must be verified via OTP as part of the attacker profile setup.
If the number is registered on Telegram →
The OTP will be delivered via Telegram chat.
Note: Ensure that Two-Factor Authentication (2FA) is disabled on the number to receive the OTP on Telegram.
If the number is not registered on Telegram →
The OTP will be delivered via SMS.
Enter the customised phishing message.
Use variables to personalise the message:
First Name: {{.fname}}
Last Name: {{.lname}}
URL: {{.URL}}
Upload an image, if required, to enhance the message.
If Credential Harvesting is enabled:
Configure the landing page according to customer requirements.
Select appropriate checkboxes for:
Data collection fields
Awareness page redirection (if applicable)
Click on "Go to Next" to preview the template.
Review all configurations.
Click "Finish" to save the template.
Open the newly created Telegram template.
Click on "Create Campaign".
Assign a Campaign Name.
Select the Target User Group.
Set the Campaign Expiry Date.
Click "Send Now" to launch the campaign to the selected user group.
Telegram-based phishing simulations will only work if the user has the Telegram app installed and accessible on their mobile device.
If the app is not installed or accessible, the user will not receive the message, and the simulation will not be delivered.
This process ensures accurate configuration and execution of the Telegram phishing simulation, enabling effective testing while aligning with customer requirements. If you need any further assistance or clarification, feel free to reach out!