September 2026 — Methodology baseline & pattern catalog
This baseline defines how BeefyGuard will publish monthly impersonation reports. Future editions will add aggregate counts from opted-in telemetry where available. This edition focuses on methodology + attack pattern catalog so defenders and researchers can cite something concrete today.
Scope
- In scope: Telegram group admin impersonation — name clones, username lookalikes/homoglyphs, profile-photo copies used to enable DM scams.
- Out of scope: On-chain exploit writeups, non-Telegram channels, and any content that could identify victims or private groups.
Methodology (v1)
- Anonymization: No usernames, user IDs, group IDs, wallet addresses, or raw message text from victims.
- Pattern labels: Incidents (when published) are tagged with one or more pattern IDs from the catalog below.
- Counts: Future reports may include totals such as "detections actioned" across participating groups. Counts will note sample size and date range.
- False positives: When we discuss rates, we will separate auto-bans from alert-only events and note whitelist overrides where relevant.
- Honesty: We do not claim to stop private DMs. Success = clones removed in-group + members trained not to trust unsolicited admin DMs.
Pattern catalog (v1)
| ID | Pattern | What defenders see |
|---|---|---|
| NAME-EXACT | Exact display-name clone | Same visible name as an admin; different account |
| NAME-SIM | Near-duplicate display name | 1–2 character edits, swapped letters |
| UNAME-HOMO | Homoglyph username | Unicode lookalikes (e.g. Cyrillic/Latin mixes) |
| PHOTO-MATCH | Profile photo clone | Avatar matches or closely matches an admin photo |
| COMBO | Multi-signal clone | Name/lookalike + photo together (highest confidence) |
| SUPPORT-THEATER | DM support pretext | Member reports "admin" DM after public question (reported, not read by bot) |
Defender actions this month
- Pin the never-DM-first rule ([Trust](/trust)).
- Sync admins after every staff change.
- Enable name + lookalike + photo detection ([Features](/features)).
- Read the [fake admin scam guide](/blog/telegram-admin-impersonation-scams-guide).
Next report
Target cadence: monthly. Next edition will add the first aggregate detection counts once sampling is stable. Canonical index: https://beefyguard.com/reports.