For anyone wondering: the attacker needs physical access to your unlocked device, and replaces the telegram.org URL with a telegramz.org URL. The authentication part is stored in a string after the domain name... and the attack server gets it.
Author's video demo here: https://vimeo.com/941755175