← All reports

September 2026 — Methodology baseline & pattern catalog

This baseline defines how BeefyGuard will publish monthly impersonation reports. Future editions will add aggregate counts from opted-in telemetry where available. This edition focuses on methodology + attack pattern catalog so defenders and researchers can cite something concrete today.

Scope

  • In scope: Telegram group admin impersonation — name clones, username lookalikes/homoglyphs, profile-photo copies used to enable DM scams.
  • Out of scope: On-chain exploit writeups, non-Telegram channels, and any content that could identify victims or private groups.

Methodology (v1)

  1. Anonymization: No usernames, user IDs, group IDs, wallet addresses, or raw message text from victims.
  2. Pattern labels: Incidents (when published) are tagged with one or more pattern IDs from the catalog below.
  3. Counts: Future reports may include totals such as "detections actioned" across participating groups. Counts will note sample size and date range.
  4. False positives: When we discuss rates, we will separate auto-bans from alert-only events and note whitelist overrides where relevant.
  5. Honesty: We do not claim to stop private DMs. Success = clones removed in-group + members trained not to trust unsolicited admin DMs.

Pattern catalog (v1)

IDPatternWhat defenders see
NAME-EXACTExact display-name cloneSame visible name as an admin; different account
NAME-SIMNear-duplicate display name1–2 character edits, swapped letters
UNAME-HOMOHomoglyph usernameUnicode lookalikes (e.g. Cyrillic/Latin mixes)
PHOTO-MATCHProfile photo cloneAvatar matches or closely matches an admin photo
COMBOMulti-signal cloneName/lookalike + photo together (highest confidence)
SUPPORT-THEATERDM support pretextMember reports "admin" DM after public question (reported, not read by bot)

Defender actions this month

  • Pin the never-DM-first rule ([Trust](/trust)).
  • Sync admins after every staff change.
  • Enable name + lookalike + photo detection ([Features](/features)).
  • Read the [fake admin scam guide](/blog/telegram-admin-impersonation-scams-guide).

Next report

Target cadence: monthly. Next edition will add the first aggregate detection counts once sampling is stable. Canonical index: https://beefyguard.com/reports.