The campaign reportedly targeted visitors through Brevo’s embedded tracker, chat widget, hosted forms, and unsubscribe pages.
A Telegram Desktop flaw lets bots inject JavaScript into exported chats, enabling data theft and page manipulation.