Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

PNB MetLife Phishing Attack: Multi-Stage Scheme Steals Data, Triggers UPI Payments

A multi-stage phishing campaign has been identified targeting PNB MetLife Insurance customers using counterfeit payment gateway pages. This campaign is designed to extract customer details, facilitate fraudulent UPI payments, and escalate to the…

A multi-stage phishing campaign has been identified targeting PNB MetLife Insurance customers using counterfeit payment gateway pages. This campaign is designed to extract customer details, facilitate fraudulent UPI payments, and escalate to the harvesting of full banking credentials. Attackers exploit customer trust in the brand, utilizing free hosting services and Telegram bots for real-time data exfiltration.

The fake pages are optimized for mobile devices, suggesting SMS-based delivery as a potential vector. Analysis shows no legitimate payment processing backend; all user interactions are meant for data theft.

Multiple phishing templates have been deployed on EdgeOne Pages, a free hosting service, impersonating the official PNB MetLife premium payment gateway.

Hosting Platform: EdgeOne Pages (Free hosting for rapid deployment) Telegram Exfiltration Bot: @pnbmetlifesbot – Initial data collection Advanced Harvesting Bot: @goldenxspy_bot – Banking credential theft Operator Account 1: @darkdevil_pnb – Real-time monitoring Operator Account 2: @prabhatspy – Data recipient account Delivery Method: SMS (likely primary infection vector)

The first phishing variant presents a mobile-friendly form requesting name, policy number, and mobile number. Importantly, the page lacks input validation, accepting arbitrary values without verification. Once submitted, data is silently exfiltrated via Telegram Bot API. Victims are then prompted to enter a payment amount, which also lacks validation, leading to a UPI-based payment flow with a dynamically generated QR code to create urgency.

A multi-stage phishing campaign has been identified targeting PNB MetLife Insurance customers using counterfeit payment gateway pages.
Sarah Dawson · Thehackingpost

Buttons for PhonePe and Paytm use clipboard abuse techniques, silently copying attacker-controlled UPI IDs to the clipboard before redirecting users to payment app deep links, increasing the success rate of fraud completion.

Stage 2: Advanced Credential Harvesting Template

This variant goes beyond payment fraud, presenting options such as "Update Amount," "Refund Your Amount," and "Add AutoDebit System," simulating legitimate policy servicing. Upon selecting "Update Amount," users enter a new premium amount and proceed to a "Bank Details for Verification" page, where all banking and card details are exfiltrated via goldenxspy_bot to the operator account @prabhatspy , escalating the campaign to comprehensive financial credential harvesting.

Data Collection: Unvalidated form inputs capture customer information. Silent Exfiltration: Hardcoded Telegram bot tokens and chat IDs transmit data in real-time. Dynamic QR Generation: JavaScript renders UPI payment URIs as QR codes. Clipboard Manipulation: Attacker-controlled UPI IDs are silently copied to the clipboard. App Redirection: Deep links push victims into legitimate payment apps with the attacker’s UPI ID pre-populated.

There is no backend validation at any stage, confirming the infrastructure exists solely for fraud.

Advertisement

For Users: Avoid clicking premium payment links from SMS messages; always navigate directly to PNB MetLife’s official website using a bookmarked URL. For Enterprises: Implement email and SMS filtering to block malicious domains; educate customers on phishing indicators. For Platforms: Block EdgeOne Pages subdomains hosting phishing kits; monitor Telegram bots for financial credential theft. For Law Enforcement: Coordinate with Telegram and hosting providers for immediate takedown; track operator accounts for attribution.

This campaign illustrates a sophisticated understanding of mobile fraud mechanics and psychological manipulation. The abuse of free hosting platforms, legitimate payment apps, and real-time Telegram exfiltration creates a low-friction fraud operation targeting a major insurance company in India.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories