Threat Investigation: Touch 'n Go QR Phishing Campaign Targeting Telegram Account Takeover

Executive Summary This report documents an investigation into a localized phishing (“quishing”) campaign distributed on the Threads platform. The Threat Actor used a fake Touch ’n Go (TNG) “Money Packet” QR code to lure victims to a newly established, Cloudflare-proxied domain. Initial passive OSINT suggested a conventional credential-harvesting site. Further manual live forensics showed that the true objective is full Telegram account takeover, not theft of TNG eWallet credentials. The TNG branding is only the pretext. The backend relays the victim’s phone number to the real Telegram login system and then solicits the resulting one-time passcode (OTP) and two-factor (2FA) password. ...

October 7, 2026