Soldiers are being turned into persistent intelligence sources the moment they trust the wrong chat contact. Once the lure works, the phone or Telegram session keeps giving up messages, files, location data, and even microphone audio long after a password change would feel like the problem is fixed.
Researchers say SiribClone has been active since at least summer 2025 and has targeted Russian servicemembers in border regions and combat zones. The group used romance and volunteer pretexts on Telegram and other messaging apps to push malicious apps or steal Telegram codes on fake login pages; the resulting Android spyware and desktop file-stealing malware were built to pull photos, documents, and chats, and in some cases to store stolen Telegram sessions for later review.
The larger risk is not a single account takeover but a live source of battlefield intelligence sitting on a personal device. That makes personal phones and chat apps operationally sensitive in a way standard account-security thinking misses.