News

Telegram as Criminal Infrastructure: How Threat Actors Use Channels for Data Sales, C2, and Recruitment

Telegram hosts criminal marketplaces, C2 channels, and stolen data dumps. How security teams monitor Telegram for actionable threat intelligence in 2026.
Sami Malik
Copywriter

In August 2024, French authorities arrested Telegram founder Pavel Durov on charges related to the platform's failure to moderate criminal activity. The arrest focused international attention on what security researchers had been documenting for years: Telegram, with over 950 million monthly active users as of 2024, had become the most accessible criminal communication platform in the world. Not because it was built for crime, but because its combination of large public channels, automated bot infrastructure, and minimal content moderation had made it more operationally convenient for criminal operators than traditional dark web forums requiring Tor browsers and manual registration.

The arrest prompted Telegram to announce increased cooperation with law enforcement requests, and analysts observed some migration of criminal operators to alternative platforms including Session and Matrix-based services. But the underlying infrastructure, hundreds of criminal channels with tens of thousands of subscribers, the automated bot storefronts, and the command-and-control channels woven into the platform's legitimate traffic, did not disappear. Understanding how Telegram functions as criminal infrastructure is a precondition for monitoring it effectively.

The Architecture of a Criminal Telegram Channel

Criminal Telegram channels operate in a tiered structure that mirrors legitimate media organisations. At the top sits the broadcast channel, a one-way communication tool where the operator posts announcements: new data dumps available for purchase, service updates, pricing changes, and operational security reminders to buyers. Below that, the associated group chat functions as the customer service layer, where buyers ask questions, dispute orders, and provide feedback on purchase quality. Some operators run a third tier: a private VIP channel accessible only to verified repeat buyers, where higher-value data or advance notice of fresh leaks is posted before public announcement.

The naming conventions of criminal channels are deliberate. Operators avoid terms that would trigger Telegram's automated moderation and instead use abbreviations, coded language, or innocent-sounding names. A channel selling stealer logs might present as a "cloud asset management service" or "data analytics provider." The actual criminal function is communicated through channel descriptions, pinned messages, and bot interactions that automated moderation does not consistently flag. This means that finding and evaluating criminal Telegram channels requires human analysts who understand the vernacular and can assess credibility signals that automated systems miss.

Channel subscriber counts provide a rough proxy for operator reputation and operational history, though the purchase of fake subscribers distorts this metric. A channel with 50,000 subscribers and posts dating back two years signals a more credible criminal operation than one with 500 subscribers and posts from the previous month. For threat intelligence analysts evaluating whether a claimed breach of their organisation is genuine, the operator's channel history is the first credibility signal to assess.

What Criminal Operators Sell on Telegram

Stolen credential sales represent one of the highest-volume categories on criminal Telegram channels. A typical listing includes a sample of the stolen data, the record count, the claimed source, and the price in Bitcoin or Monero. Monero is increasingly preferred by security-conscious operators because of its stronger transaction privacy relative to Bitcoin. Some operators offer escrow services through trusted third-party accounts within the criminal community to reduce buyer risk on high-value transactions.

Infostealer log collections have become the dominant data product on criminal Telegram channels. Rather than selling access to a single breached database, log sellers offer collections of data exfiltrated from individual infected machines: browser-saved credentials from dozens of accounts, cryptocurrency wallet files, session cookies, and system information. Group-IB's research has documented the consistent growth of stealer log listings across criminal markets and Telegram channels, reflecting both increased infostealer malware deployment and Telegram's efficiency as a distribution channel.

Beyond credentials, criminal Telegram channels sell phishing kit templates targeting specific banks, retailers, and government portals, complete with hosting support and update services. Fake document templates for identity fraud, including driving licences, passports, and utility bills from dozens of countries, are offered at prices as low as a few dollars per template. Access to compromised business email accounts is sold as a premium product category, with pricing reflecting the seniority of the compromised account holder and the industry of the organisation.

Command-and-Control Infrastructure via Telegram Bots

One of the most technically significant ways threat actors use Telegram is as command-and-control infrastructure for active malware. The Telegram bot API provides a free, reliable, authenticated communication channel that malware can use to receive operator instructions and send exfiltrated data back to the attacker. Because Telegram's servers are operated by a legitimate, high-reputation company, outbound traffic to Telegram's domains passes through corporate firewalls that would block connections to attacker-controlled servers or known malicious infrastructure.

A March 2026 FBI advisory documented Iranian MOIS cyber actors deploying multi-stage Windows malware that used Telegram bots as its entire command-and-control infrastructure. The second stage of the payload connected infected machines to Telegram bots operated by the attackers, enabling screen capture, file exfiltration, and remote access — all channelled through Telegram's legitimate API. The attackers needed only a bot token and a chat ID to receive stolen data and issue commands from anywhere. Because the C2 traffic ran over Telegram's own servers, network-level detection required either blocking Telegram entirely or deploying deep packet inspection capable of distinguishing normal application traffic from attacker-controlled bot traffic, neither of which is practical for most organisations.

Redline Stealer, one of the most widely deployed infostealer malware families of recent years, has in some campaign configurations used Telegram bots to deliver stolen credential logs directly to the operator, reducing the infrastructure footprint required and eliminating the need for attacker-controlled panels that could be taken down by hosting providers or law enforcement. For defenders, detecting Telegram-based C2 requires endpoint-level monitoring for processes making outbound connections to Telegram API endpoints without a corresponding legitimate application context.

Recruitment and Operational Coordination

Criminal organisations use Telegram not only for selling data but for recruiting and coordinating operations. Ransomware affiliate programmes post recruitment notices seeking technically skilled operators willing to deploy ransomware in exchange for a revenue share. Money mule recruitment, the solicitation of individuals willing to receive and forward stolen funds through their bank accounts, is conducted openly on channels presenting themselves as remote work or investment opportunities.

KillNet, the pro-Russian hacktivist collective that conducted distributed denial-of-service attacks against European and North American targets throughout 2022 and 2023, organised its operations almost entirely through Telegram channels. The group announced targets, coordinated attack timing, and posted results for public visibility through Telegram, amassing hundreds of thousands of subscribers at its peak. Telegram functioned simultaneously as an operational planning tool, a propaganda broadcast mechanism, and a recruitment platform for a hacktivist operation that attracted media coverage disproportionate to its actual technical capability.

How Security Teams Monitor Telegram for Threat Intelligence

Monitoring Telegram for threat intelligence requires a combination of human analyst access, automated channel scraping, and keyword alerting, each with distinct technical and operational constraints. The most direct approach, joining criminal channels and monitoring them manually, provides the highest-fidelity intelligence but is operationally intensive and requires analysts who can identify credible channels, assess operator reputation, and distinguish genuine threats from fraudulent listings.

Automated Telegram monitoring collects messages from accessible public channels and applies keyword matching and classification to identify mentions of target organisations, infrastructure identifiers, and brand terms. The limitation of automated monitoring is that the most sensitive criminal intelligence circulates in private channels and groups that require invitation or purchased access. Public channel monitoring captures the criminal marketplace's visible layer, not its private negotiations and advance planning activity.

Keyword alerting on Telegram targets organisation-specific indicators: domain names, email address patterns, IP ranges, employee names, and registered brand terms. When these appear in monitored channels, analysts receive alerts requiring triage to determine whether the mention represents a genuine threat, a fraudulent claim, or a coincidental reference. For large organisations with high brand visibility, the volume of Telegram mentions can be substantial, requiring automated pre-filtering to surface only actionable alerts.

The Intelligence Value of Telegram Monitoring

For security teams, Telegram monitoring provides intelligence that internal tools cannot generate: warning of threats at the planning and preparation stage, before an attacker attempts to use stolen credentials or launch an attack. An alert that your organisation appears in a criminal Telegram channel listing what is claimed to be employee credentials is actionable intelligence that enables password resets, MFA enforcement, and incident response preparation before the credentials are weaponised.

The Durov arrest in 2024 demonstrated that Telegram's criminal infrastructure is not immune to external pressure. But it also demonstrated the platform's resilience: despite increased scrutiny, criminal channels continued to operate, and the migration to alternative platforms was partial and incomplete. For defenders, this means Telegram monitoring remains an essential component of dark web and external threat intelligence programmes in 2026, alongside monitoring of alternative platforms that criminal operators have begun to adopt.

Assessing the Credibility of Telegram Criminal Channels

Not every Telegram channel claiming to sell corporate data represents a genuine threat. A significant proportion of criminal channels are operated by fraudsters who sell fabricated or repackaged data to buyers who cannot verify authenticity before payment. For threat intelligence analysts, distinguishing credible operators from fraudsters is a core analytical skill that determines whether a Telegram-sourced alert warrants immediate escalation or lower-priority investigation.

Credible criminal Telegram channels typically exhibit several characteristics. They post verifiable samples: small excerpts of data that a buyer can partially validate before purchase. They have a consistent operational history with posts dating back months or years. They maintain references or reputation scores on other criminal platforms, with vouches from community members. And they apply consistent operational security practices, such as using coded language for sensitive details and avoiding direct victim identification in public posts.

Fraudulent channels, by contrast, frequently post data that is identical to known public breaches repackaged with new branding, claim access to high-profile targets without verifiable samples, request upfront payment with no escrow protection, and disappear after collecting payment. For defenders, a fraudulent channel claiming to possess your organisation's data is not a security incident. But it may require communications work if the claim becomes public and affects customer confidence, making rapid assessment of channel credibility a prerequisite for an informed response.

The intelligence assessment process for a Telegram-sourced alert should answer four questions: Is the operator credible based on their history? Does the claimed data appear genuine based on available samples? Does the claimed material represent new data or a re-listing of previously known breaches? And does the data represent a material risk to the organisation, or does it contain only low-sensitivity information? Only after answering these questions can a security team determine the appropriate response priority and allocate resources accordingly.

Defendis maintains continuous assessment of criminal Telegram operator credibility as part of its external threat intelligence monitoring service. When a Telegram alert involves your organisation, the intelligence includes a credibility assessment of the operator, a comparison of the claimed data against known previous breaches, and a recommended response priority based on assessed material risk.

The Role of Telegram Administrators and Channel Hierarchies

Telegram criminal operations have developed organisational structures that mirror the management hierarchies of legitimate businesses, with administrators, moderators, and tiered access controls that determine who can post, who can view restricted content, and who can transact. Understanding these structures is operationally relevant for threat intelligence teams because it informs how information flows within criminal Telegram communities and what level of access is needed to reach the most sensitive intelligence.

Top-tier criminal channels are typically administered by groups that have established reputations across multiple platforms over years. The administrators vet new members, manage disputes between buyers and sellers, and maintain the channel's reputation for quality by banning fraudulent actors. These reputation management activities are what create the trust that makes criminal Telegram markets function; without administrator enforcement of quality standards, channels would quickly become unusable due to fraud. For threat intelligence analysts, the administrators of major criminal channels are high-value nodes in the threat intelligence graph: their activity patterns, their relationships with other criminal actors, and the intelligence they post or curate are more valuable than the activity of individual buyers and sellers.

Channel hierarchies often include free public announcement channels, paid subscription channels with more detailed intelligence, and private invitation-only channels for the most sensitive material. This tiered structure means that monitoring public Telegram channels provides only a fraction of the intelligence available within the criminal ecosystem. Specialist threat intelligence providers with established presences in these communities have access to tiers that passive monitoring of public channels cannot reach, which is why community access and established relationships are part of the core competency of effective dark web and Telegram monitoring services.

Frequently Asked Questions

How do criminal actors use Telegram differently from the dark web?

Telegram provides faster access, larger potential audiences via public channels, and more resilient infrastructure than Tor-hosted dark web forums. Criminal actors use Telegram for time-sensitive operations, high-volume data sales, and recruiting, while the dark web remains preferred for more sensitive transactions requiring vetting and reputation-based access. The two ecosystems increasingly overlap as many dark web communities maintain companion Telegram channels for announcements and pre-vetting of new members.

Can Telegram take down criminal channels?

Telegram does remove channels that violate its terms of service, but enforcement has historically been inconsistent and criminal actors adapt quickly by maintaining backup channels and migration paths for community members. A criminal channel removed from Telegram typically migrates its audience to a new channel within hours, often with an announcement sent to members via bot before the removal. This resilience means takedowns have limited sustained impact on well-established criminal communities, making intelligence monitoring more valuable than relying on platform takedowns as a primary defence.

What types of organisations are most exposed to Telegram-based threats?

Financial services, retail, and technology companies face the highest volume of Telegram-based threats due to the value of their customer data and credentials. Healthcare organisations are increasingly targeted, particularly for patient data that commands high prices on criminal markets. Any organisation with significant brand recognition is also at risk from Telegram-based fraud operations that use the organisation's branding to target its customers, independently of whether the organisation itself is ever breached.

How quickly can stolen credentials from Telegram be used in attacks?

Stolen credentials published on Telegram can be purchased and used within minutes. Automated credential stuffing tools allow attackers to test large credential lists against multiple services simultaneously, meaning that a credential dump published at midnight may have been fully tested across hundreds of services by morning. For organisations whose employees' credentials appear in these dumps, the window between publication and first exploitation attempt is extremely short, making automated monitoring and automated response (forced password resets) the only practical defence at the speed required.

Building Actionable Intelligence from Telegram Monitoring

The operational challenge in Telegram monitoring is not collection volume but signal extraction: the sheer quantity of content across criminal channels requires automated filtering and analytical triage to identify what is genuinely relevant from what is noise. A security team that receives raw Telegram data without analytical enrichment faces the same problem as one monitoring raw network logs without SIEM correlation rules, an information overload that reduces effective detection capability rather than improving it.

Effective Telegram intelligence workflows begin with precise keyword and pattern filters calibrated to the organisation's specific risk profile: email domain patterns, IP ranges, product names, executive names, and technology stack identifiers that would appear in data about the organisation. These filters reduce the monitoring surface from the full Telegram criminal ecosystem to the subset of content that requires human analyst attention. The filtered alerts are then enriched with context from the threat intelligence platform, connecting a specific credential dump to previous activity by the same threat actor, or linking a newly posted access listing to a known IAB whose targeting patterns match the organisation's sector.

The output of an effective Telegram intelligence workflow is not a list of raw channel posts but a prioritised set of actionable items: credentials that need immediate reset, access listings that require verification against internal indicators of compromise, and campaign announcements that require briefing to the incident response team. The workflow that transforms raw Telegram monitoring into these actionable outputs is what distinguishes a threat intelligence programme from a data collection activity, and it requires the same analytical investment as any other intelligence discipline. Defendis delivers the Telegram intelligence signal after this analytical transformation, with the context needed to act, rather than raw data requiring in-house processing.

How Defendis Monitors Telegram and Malware Infrastructure for Your Organisation

The criminal activity described in this article, from Telegram data sales to active malware campaigns targeting corporate environments, leaves detectable traces that Defendis monitors continuously. Defendis tracks criminal Telegram channels, malware campaign infrastructure, and credential exposure sources to surface alerts before leaked access or active malware reaches your environment. When your organisation's credentials, session tokens, or infrastructure indicators appear in a Telegram dump or malware campaign, Defendis delivers a targeted alert with enough context to act immediately.

Request a demo to see how Defendis surfaces Telegram-sourced intelligence and malware exposure specific to your organisation.

About the author
Sami Malik is a copywriter passionate about crafting clear, engaging, and impactful content that helps brands connect with their audience through storytelling and strategy.

Related Articles

Discover simplified
Cyber Risk Management
Learn how to prevent cyberattacks proactively with a free trial of Defendis.