As we wrote in previous Dark Web Pulse posts, many other cyber-criminal groups, such as RansomHouse, Arvin Club, Lapsus , BlackShoadow, GhostSec, Moses Staff, and more, use Telegram. Your account must be older than 4 days, and have more than 20 post and 10 comment karma to contribute. Please note that the site is automatically filled from open sources and does not store information about Telegram channels except for the name, description, link, and avatar. If you come across a Telegram channel that violates the law, please contact us using the contacts listed in the site menu. After reviewing the complaint, we will remove this Telegram channel from the search.
Some might argue that Telegram’s privacy features mean that the company does not have much data about this activity to report to police. Telegram says that its moderation is “within industry standards”, but this week we have seen evidence to the contrary related to an area of criminality far less visible (and one I did not search for) – child sexual abuse material. Read this Dark Web Pulse to see examples of illicit content on Telegram and a thorough breakdown of why threat groups prefer instant messaging. Even though they can be sold for just a couple of dollars, browser fingerprints and stealer logs can represent the digital lives of their victims. With saved login credentials and more (especially combined with OSINT), a threat actor could even guess the victim’s general geographic location. Threat actors distribute stealer logs in various ways depending on the channel.

Example #2: Cybercriminal Groups Activities
As the app doesn’t have a solid registration process, anyone could just simply sign up on Telegram. The similarities between Lulzsec, LAPSUS$, and the new group, SiegedSec are noteworthy – as SiegedSec’s leader, YourAnonWolf uses similar popular hacking culture phrases that LulzSec’s member, Topiary used. The group’s members, ranging in age between 18 and 26 years old, were all sentenced in 2013 between 20 and 32 months for violation of the UK’s computer misuse act in conjunction with the cyber campaigns they conducted. Some of its members were banned from the Internet for upwards of two years and spent time in the Young Offender’s Institute to be reformed. We discovered a Keybase “team account” that claims the group has 7 active members. A privacy researcher, Matt Brown of Brown Fine Security, found a number of vulnerabilities in Motorola Reaper HD license plate readers.
Telegram’s Dark Web Channels: A Growing Hub For Cyber Threats
The platform offers Live Traffic, delivering logs in real time, and Private Cloud, which provides up to 5,000 logs daily, amounting to 120,000 logs per month. Additionally, Omega Cloud maintains a database exceeding 2 billion records, accessible through a subscription-based model. A Telegram channel specializing in the distribution of credentials obtained from stealer logs.
Telegram Emerges As New Dark Web For Cyber Criminals

In recent years, Telegram has become a popular messaging platform for both illicit and legitimate communication activities. The app has allowed people from all over the world to be able to share and collaborate more than ever before. However, it has also allowed numerous dark web forums and other nefarious groups to move onto the messaging app as well and create illicit channels successfully. Telegram, unlike some other messaging apps, provides end-to-end encrypted chats when a user selects the “Secret Chats” option in their settings. The content inside channels and groups is then encrypted between Telegram and its server, meaning ISPs can’t access any data.

Bitcoin News Crypto &a
Any flagged items are reported to security vendors, blocklists, and targeted organizations, identified using the 7+ Million Company dataset. She said Telegram has become “a preferred platform for censored and illegal activities” because the platform’s founders have resisted attempts to censor its content or share information with authorities and due to the availability of shopbots which speed up sales. While it might tempt you to visit dark web Telegram groups and channels, understand the risks—phishing, fake NFTs, bogus crypto investment schemes, etc.—and stay away from this content. Users can access this content through the regular Telegram app and become victims of fraud or get in trouble with the law.
By open-sourcing our dataset and the DarkGram model, we provide a valuable foundation for continued investigation and collaboration in the fight against cybercrime. Using the two tools, found 1,210 files to be malicious, out of which only 491 (4̃0%) had been priorly scanned by Hybrid Analysis, suggesting several of the malicious files shared in the CACs had not been seen by the tool. Considering Hybrid Analysis is a popular tool which contributes threat intelligence to antivirus vendors, there is a possible detection gap for these files. We cross-referenced the APKs with those listed in the AndroZoo repository (Allix et al., 2016), using package names to avoid discrepancies caused by modified file hashes. Interestingly, we found that 83 of the malicious APKs had corresponding entires available on the Google Play Store indicating Telegram’s role in distributing repackaged or potentially malicious apps.
So too are some of the criminals on the Telegram groups I am now a member of, with FreeDurov imagery being shared in English and Russian widely. In spite of all the criticism against Telegram’s approach to moderation, there are some who are concerned that Mr Durov’s arrest is a troubling time. Its approach to police requests to remove illegal content and pass on evidence is another criticism. In January, state police in Latvia set up a separate unit specialising in monitoring chat apps for drug trafficking and communication, and officials have named Telegram as a particular concern. “We are talking about child sexual abuse material, we’re talking about drug sales, we’re talking about absolutely dark web levels of criminality that they’re just doing nothing about,” he said.

Darknet Telegram Directory
The battle against piracy and the protection of copyright have become pivotal issues in the digital era. On one hand, digital technologies have enabled widespread copyright infringement; on the other, they have facilitated the proliferation of new creative works on a massive scale (Aguiar et al., 2024; Waldfogel, 2017; Wu and Zhu, 2022). While legal measures aimed at shutting down unlicensed services have had success (Danaher and Smith, 2014; Danaher et al., 2019), alternative platforms emerge to replace those that are taken down (Aguiar et al., 2018; Lauinger et al., 2013). However, these systems are not without flaws, often leading to the overblocking of legitimate uses, including content that falls under the fair use doctrine (Urban et al., 2017; Erickson and Kretschmer, 2018). Jacques et al.(Jacques et al., 2018) provided a comprehensive critique of fully automated anti-piracy systems (AAPS), noting that these systems often fail to account for copyright exceptions, leading to the removal of lawful content.
Ready To Explore Web Data At Scale?

However, with millions of Telegram users posting terabytes of content each day, moderation is a herculean process. Concerns regarding data handling also persist, and reports of user data being turned over to foreign authorities in Germany have raised concerns about privacy implications. These incidents reveal the ongoing struggle between Telegram’s privacy promises and the practicalities of managing illegal activities.
Could US Government Ban Apps Which Track ICE Agents?
In some cases this may be for free and in other cases the credentials may be purchased through automated mechanisms on specific channels. Primarily focused on DDoS attacks, Dark Storm Team follows an opportunistic targeting strategy across various sectors. In addition to its cyber operations, the group also promotes hacking services for hire through its Telegram channel, offering DDoS attacks on protected websites and database dumps from organizations such as banks and airports.
How To Access Channels Or Groups On Telegram?
Since July of last year, Elliptic has highlighted the enormous volume of money laundering and other illicit transactions taking place on Huione Guarantee and later Haowang Guarantee. By Elliptic’s accounting in a January report, the market and its rebrand had facilitated more than $24 billion in total transactions, which would make it by far the largest single black market operation in the internet’s history. The LAPSUS$ Telegram group is home to hackers who attack governments and tech companies worldwide. Recently investigated LAPSUS$, which also posts content on the dark web, and arrested seven suspects for cyber crimes. Even if you just poke around to see what’s happening, you could end up on a list. Narcotics Express is a closed Telegram group, meaning users must request access to view content.
- As these apps become a major tool for cybercriminals, monitoring them alongside dark web sites has become crucial as part of seeing threats before they harm your organization.
- It’s not about all the illegal or illicit stuff, the dark web is also used by political whistle-blowers, activists, and journalists who may be censored or could risk political retaliation if discovered by their government.
- WIKILEAKS is also the result of the dark web.Dark websites don’t come up in search results when looked up on search engines like Google.
- While Telegram was once a safe haven for illicit activity, recent policy changes have forced many threat actors to reconsider their presence on the platform.
- Its user-friendly interface and widespread adoption make it more reachable to a broader audience, including both legitimate and illicit users.
Telegram’s Dark Web Channels
- This was due to the WhatsApp privacy scandal in 2021, where it was claimed that WhatsApp is sharing its users’ data such as their phone numbers, transaction data, and other service-related information with its parent company, Facebook.
- It highlights the platform’s role as a contemporary Hades, a space where the boundaries of privacy and criminality blur, and considers the broader implications for security and regulation.
- In some cases this may be for free and in other cases the credentials may be purchased through automated mechanisms on specific channels.
- Now based in Dubai, Telegram was started in 2013 by Russian brothers Pavel and Nicolai Durov and now has 700 million active monthly users.
- This focus on personal OpSec underscores the challenges faced by cybersecurity professionals attempting to monitor and disrupt these activities.
Dark Storm Team is a hacktivist threat group known for its pro-Palestinian cyber activities and past collaborations with groups such as Anonymous Sudan. The group has carried out cyberattacks against Denmark, Egypt, France, Israel, the UAE, and the United States, frequently working alongside other threat actors. Established in April 2019 as a Russian-language group, EMP/mailpass/sqli Chat has since expanded into a global cybercrime discussion channel.