Characterizing and Detecting Propaganda-Spreading Accounts on Telegram
Klim Kireev
34th USENIX Security Symposium (USENIX Security '25) · Day 1 · Social Issues and Usable Security and Privacy
Overview
This distinguished paper from USENIX Security 2025, titled "Characterizing and Detecting Propaganda-Spreading Accounts on Telegram," addresses the critical and evolving cybersecurity threat of information-based attacks, specifically propaganda, on instant messaging platforms. Given that much security research has historically focused on traditional social media like X (formerly Twitter) and Reddit, the unique architecture and moderation challenges of platforms such as Telegram have often been overlooked. The authors, Klim Kireev, Yevhen Mykhno, Carmela Troncoso, and Rebekah Overdorf, present a comprehensive study that not only characterizes the behavior of propaganda accounts on Telegram but also introduces a novel and highly effective detection mechanism.
Read the paper · Download the PDF (PDF) · Slides
Paper abstract
Information-based attacks on social media, such as disinformation campaigns and propaganda, are emerging cybersecurity threats. The security community has focused on countering these threats on social media platforms like X and Reddit. However, they also appear in instant-messaging social media platforms such as WhatsApp, Telegram, and Signal. In these platforms, information-based attacks primarily happen in groups and channels, requiring manual moderation efforts by channel administrators. We collect, label, and analyze a large dataset of more than 17 million Telegram comments and messages. Our analysis uncovers two independent, coordinated networks that spread pro-Russian and pro-Ukrainian propaganda, garnering replies from real users. We propose a novel mechanism for detecting propaganda that capitalizes on the relationship between legitimate user messages and propaganda replies and is tailored to the information that Telegram makes available to moderators. Our method is faster, cheaper, and has a detection rate (97.6%) 11.6 percentage points higher than human moderators after seeing only one message from an account. It remains effective despite evolving propaganda.

Characterizing and Detecting Propaganda-Spreading Accounts on Telegram
Speakers: Klim Kireev, Research Scientist, MPI-SP Max Plank Institute for Security and Privacy; Yevhen Mykhno, Researcher, unaffiliated; Carmela Troncoso, Professor, MPI-SP Max Plank Institute for Security and Privacy, EPFL; Rebekah Overdorf, Assistant Professor, University of Lausanne, Ruhr University Bochum (RUB), Research Center Trustworthy Data Science, Security in University Alliance Ruhr
Conference: USENIX Security
YouTube: N/A (This article is based on a peer-reviewed conference paper, not a recorded talk.)
Overview
This distinguished paper from USENIX Security 2025, titled "Characterizing and Detecting Propaganda-Spreading Accounts on Telegram," addresses the critical and evolving cybersecurity threat of information-based attacks, specifically propaganda, on instant messaging platforms. Given that much security research has historically focused on traditional social media like X (formerly Twitter) and Reddit, the unique architecture and moderation challenges of platforms such as Telegram have often been overlooked. The authors, Klim Kireev, Yevhen Mykhno, Carmela Troncoso, and Rebekah Overdorf, present a comprehensive study that not only characterizes the behavior of propaganda accounts on Telegram but also introduces a novel and highly effective detection mechanism.
The research highlights Telegram's role as a primary source of information in conflict zones, exemplified by the Russo-Ukrainian war, where both sides actively leverage the platform for information dissemination. Unlike algorithmic feeds, Telegram's chronological message display places the burden of moderation squarely on channel administrators, who often operate with limited tools and information. This paper fills a significant gap by providing a data-driven understanding of propaganda operations within Telegram's group and channel structures and offering a practical, actionable solution for moderators.
The significance of this work lies in its ability to deliver a robust and efficient defense against evolving propaganda tactics. By analyzing a substantial dataset of over 17 million Telegram messages, the authors uncover coordinated propaganda networks and develop a detection method that capitalizes on the relationship between legitimate user messages and propaganda replies. Their proposed system achieves a remarkable 97.6% detection rate, outperforming human moderators by 11.6 percentage points, and demonstrates resilience against new topics and even attempts at evasion. This advancement offers a vital tool for mitigating information-based attacks in instant messaging environments globally.
Background
The proliferation of information-based attacks, including disinformation campaigns and propaganda, constitutes a severe and growing cybersecurity threat. These campaigns are particularly dangerous in geopolitical conflicts, where they can have real-world consequences, affecting matters of life and death. While the security community has dedicated considerable attention to countering these threats on platforms like X and Reddit, the unique characteristics of instant messaging social media, such as Telegram, WhatsApp, and Signal, present distinct challenges that have largely been unaddressed by mainstream research.
Telegram, with over 800 million active users, functions differently from traditional social networks. Information flows chronologically within groups (multi-user chats) and channels (one-to-many broadcasting lists). Crucially, Telegram does not perform content moderation for fake news or disinformation at the platform level; this responsibility falls entirely on the owners and moderators of individual groups and channels. These moderators typically have access to limited information—primarily online status, names/nicknames, and message content—and often rely on manual efforts or rudimentary automated tools designed to filter spam or obscene content, rather than sophisticated propaganda.
Existing research on social media propaganda often falls into two categories: measurement studies that lack actionable insights for moderators, and detection methods that rely on account-specific information (like social network graphs) or topic-specific textual analysis. These approaches are largely unsuitable for Telegram. Account-specific information is often unavailable or easily manipulated, and topic-specific models fail to generalize as propaganda narratives evolve. Previous works specifically on Telegram focused on detecting propaganda in news articles spread by state-affiliated entities, not on the widespread issue of propaganda accounts commenting in channels to spread misinformation or polarize discussions. The need for a tailored, effective, and efficient detection mechanism for Telegram's unique environment was therefore pressing.
Key Findings
The research yielded several critical findings regarding propaganda operations on Telegram and the efficacy of automated detection:
- Discovery of Coordinated Networks: The study identified two independent, large-scale coordinated networks spreading propaganda: a pro-Russian network and a smaller pro-Ukrainian network. The pro-Russian network was found to send up to 5% of messages in some channels, actively engaging users and adapting its narratives over time.
- Unique Propaganda Account Characteristics: Propaganda accounts on Telegram exhibit distinct behavioral traits:
- Reactivity: They almost exclusively reply to existing user messages or channel posts (referred to as trigger messages) rather than initiating conversations.
- Username Patterns: Usernames often follow two patterns: random, meaningless strings (e.g., "arariale") or Western names combined with numbers (e.g., "John_Smith31"), differing significantly from legitimate user accounts.
- Unlinked Replies: Propaganda messages frequently lack direct linguistic connection or "bridge words" to the messages they are replying to, indicating a generic, reusable content strategy.
- Message Repetition: A key discovery was the extensive repetition of relatively long messages (over 30 characters) among propaganda accounts, a behavior rarely seen in legitimate users.
- Short Lifespan, High Activity, Multi-Channel Presence: Propaganda accounts typically have very short lifespans (over half active for less than one day) but exhibit high activity levels and participate simultaneously in multiple channels, unlike most users who stick to one.
- Comparable Effectiveness: Propaganda messages garnered replies from real users at a rate (average 0.42 replies per message) comparable to legitimate user messages (average 0.43), suggesting users do not easily distinguish propaganda from genuine human interaction (Figure 5).
- Ineffectiveness of Manual Moderation: While some channels showed aggressive manual moderation policies (e.g., 94.7% of propaganda messages deleted in RT), others were significantly less effective (e.g., 19.9% in Rudoi). Even in highly moderated channels, a non-negligible portion (5-15%) of propaganda messages remained visible, attracting user interaction. Manual moderation is also resource-intensive and exposes moderators to harmful content.
- Novel Detection Mechanism: The authors propose a novel detection mechanism, Trigger-Propaganda embeddings, which leverages the textual relationship (or lack thereof) between legitimate user messages and the replies from propaganda accounts. This method concatenates the SBERT embeddings of trigger messages and their corresponding propaganda replies, feeding them into a DNN-based classifier.
- Superior Detection Performance: The Trigger-Propaganda embeddings detector achieved a 97.4% accuracy rate, outperforming human moderators by 11.6 percentage points. It demonstrated superior performance on unseen topics (93.0% accuracy) and robust effectiveness when tested on a distinct pro-Ukrainian propaganda network (88.8% accuracy), even with differing behavioral patterns.
- Robustness to Evasion: The detection method proved robust against adversarial attempts to evade detection, such as dropping the reply-to field or changing message style/length using an LLM like GPT-4, with performance remaining high (94.0% and 95.7% respectively).
- Efficiency: The automated detector is significantly faster and cheaper than manual moderation, processing trigger-reply pairs in as little as 0.015 seconds using a GPU, compared to 1-3 seconds for a human.
Technical Deep Dive
The core of this research involved a meticulous process of data collection, labeling, characterization, and the development of a novel machine learning-based detection system.
Data Collection and Labeling:
The authors compiled the first labeled Telegram propaganda dataset, comprising 17.3 million messages from 13 diverse political and news-oriented channels. This dataset combined two collection methods:
- Historical Message Data: Using Telegram's "Export chat history" API, messages from the past 36 months or up to an API-defined limit were collected, with multiple calls ensuring no gaps.
- Real-time Message Data: A two-month real-time collection (Aug 16 – Oct 16, 2023) was performed to capture messages that moderators might have deleted, which would be absent from historical archives.
Initial labeling involved two authors independently manually labeling a subset of messages from the Rudoi channel, focusing on four key heuristic features:
- Reactivity: Propaganda accounts primarily reply to messages, not initiate conversations.
- Random or Western-looking Usernames: Usernames were either random word-like strings (e.g., "arariale") or Western names followed by numbers (e.g., "John_Smith31").
- Unlinked Replies: Messages often lacked "bridge words" or direct linguistic connection to the preceding message, suggesting generic, copy-pasted content.
- Repeated Long Messages: A crucial insight was that propaganda accounts frequently repeat long messages (over 30 characters), a behavior rare among legitimate users (Figure 1).
A high Cohen-Kappa agreement of ~95.7% between labelers indicated strong consistency. This manually labeled set was then augmented using a snowballing technique based on repeated long messages. A database of unique propaganda messages (over 30 characters) was built, and any account found to have posted these messages was checked and, if validated, labeled as a propaganda account. This process iteratively expanded the dataset of identified propaganda accounts and messages. Validation with GPT-4 further confirmed that propaganda usernames significantly differed from user-chosen names (20.3% vs 84.7% referencing existing words).
Propaganda Accounts Characterization:
The analysis of the collected data revealed several key characteristics:
- Coordination: A social graph built on shared long messages (Figure 3) showed a dense network for propaganda accounts (average degree = 11.72) with extensive message duplication across accounts and channels, strongly suggesting orchestration by a single entity. User graphs, in contrast, were sparse (average degree = 0.18).
- Lifespan: Propaganda accounts had remarkably short lifespans; over 50% were active for less than one day, a stark contrast to legitimate users (Figure 4).
- Activity: Despite short lifespans, propaganda accounts were highly active, often sending more than 10 messages within 24 hours, compared to over 70% of users sending fewer than 10 messages in total (Figure 6).
- Channel Participation: Propaganda accounts were active in multiple channels simultaneously, while most users stuck to one (Figure 7).
- Message Length: Propaganda messages were typically of medium to large length (10-1000 characters), distinct from the very short or very long messages often posted by users (Figure 8).
- Trigger Message Language: Propaganda accounts predominantly targeted trigger messages related to politics and the Russo-Ukrainian war, sharing similar vocabulary with propaganda messages themselves (Figure 9).
- Topics: Propaganda messages covered diverse topics, clustered into four broad groups (Figure 11):
- Generic Propaganda: Pro-Russian government narratives, criticism of Zelensky, Russian domestic issues (corruption, healthcare, wages, demography), and social topics (vaping, feminism, cryptocurrency).
- Predictable Events: Messages related to national holidays or government events.
- Unpredictable Events: Reactions to recent events like the Wagner Group rebellion, Israeli-Palestinian conflict, or minor internal Russian incidents.
- Emotional Reactions: Condolences, despair, or agreement with pro-Russian statements.
- Topic Temporality: Around 40% of topics were persistent, while 20% were ephemeral, tied to specific events and active for less than a month (Figure 10).
Propaganda Detection Mechanisms:
The authors designed several machine learning classification models, restricted to information available via Telegram's Bot API (account info, message metadata, message content). Account information was excluded due to its manipulability.
- Handcrafted Features: Utilized features common in bot/spam detection, such as message length, number of words, URLs, emojis, exclamation/question marks, message time, and reply latency. An XGBoost model was trained on these features.
- Propaganda Embeddings: Leveraged SBERT embeddings (pre-trained on Russian language datasets) of the propaganda message content, fed into a 3-layer DNN.
- Trigger Embeddings: Similar to propaganda embeddings, but used SBERT embeddings of the trigger message content.
- Trigger-Propaganda Ensemble: Combined the outputs of the propaganda embeddings and trigger embeddings classifiers.
- Trigger-Propaganda Embeddings (Novel Approach): The most effective method, this concatenated the SBERT embeddings of both the trigger message and the corresponding propaganda reply. This combined embedding was then fed into a DNN-based classifier, explicitly capturing the relationship (or mismatch) between the two messages.
The models were trained on data from Aug 16 – Sep 18, 2023, and tested on data from Sep 18 – Oct 16, mimicking a realistic deployment scenario. The Trigger-Propaganda embeddings approach consistently outperformed others, achieving 97.4% overall accuracy and 93.0% accuracy on unseen topics. This highlights the critical role of understanding the relationship between user input and propaganda replies.
Demo / Proof of Concept
While this article is based on a peer-reviewed paper rather than a live conference demonstration, the rigorous evaluation of the proposed detection mechanisms serves as the empirical proof of concept. The authors meticulously tested their Trigger-Propaganda embeddings detector against various real-world scenarios, demonstrating its superior performance and robustness.
The core of the "demonstration" involved:
- Benchmarking against Human Moderators: The detector achieved an overall accuracy of 97.4%, significantly surpassing the average human moderation effectiveness of 86.0% in aggressively moderated channels (Table 3). This 11.6 percentage point improvement highlights the practical advantage of the automated system.
- Performance on Unseen Topics: The detector maintained high accuracy (93.0%) even when encountering propaganda related to new events or narratives not present in the training data (e.g., Road Development, Alcoholism, Putin's Birthday, Armenia-Azerbaijan conflict, Palestine-Israel war). This robustness is crucial for real-world deployment, where propaganda themes constantly evolve.
- Validation on a Distinct Propaganda Network: To assess generalization, the detector was evaluated on a newly discovered pro-Ukrainian propaganda network with different account behaviors (e.g., different username patterns, sporadic activity, longer lifespans, mutual "likes"). Despite these differences, the Trigger-Propaganda embeddings detector still achieved 88.8% accuracy (Table 3), proving its adaptability beyond the primary pro-Russian network.
- Robustness to Evasion Techniques: The authors simulated two adversarial evasion attempts:
- Sending messages without triggers: Artificially dropping the
reply-tofield, while significantly impacting the attacker's utility (reduced visibility), only caused a minor drop in the detector's accuracy to 94.0% (Table 5). - Changing message style/length using GPT-4: Using an LLM to rephrase and shorten propaganda messages resulted in a minimal performance degradation to 95.7% accuracy (Table 5). This suggests that cheap, automated style changes are unlikely to effectively evade the detector.
- Computational Efficiency: The detector demonstrated near real-time processing capabilities, with an average computation time of 0.015 seconds using an NVIDIA RTX 3070 GPU and 0.25 seconds on an AMD Rysen 4700G CPU. This is orders of magnitude faster than human moderation, which was estimated at 1-3 seconds per message, excluding non-online time.
These rigorous evaluations provide strong evidence that the Trigger-Propaganda embeddings method is not merely a theoretical concept but a highly effective, practical, and resilient solution for detecting propaganda on Telegram.
Defensive Implications
The findings of this research offer crucial insights and actionable recommendations for various stakeholders involved in combating information-based attacks on Telegram.
For Telegram Channel Moderators and Owners:
The most direct implication is the immediate availability of a highly effective automated tool to assist with content moderation.
- Adopt Automated Detection: Channel owners should integrate the Trigger-Propaganda embeddings detector via Telegram's Bot API. This system offers a detection rate (97.4%) significantly higher than even aggressive manual moderation.
- Improve Efficiency and Reaction Time: The detector's speed (0.015s on GPU, 0.25s on CPU) drastically reduces the time propaganda messages remain visible, minimizing their impact. This is a substantial improvement over the 1-3 seconds per message for human labeling, not to mention the inherent delays of human availability.
- Reduce Costs: Automating detection is demonstrably cheaper than employing human moderators. The cost of renting a GPU node (e.g., $0.21/hour on AWS) is considerably less than minimum wages, making advanced moderation accessible even for small, unmonetized channels.
- Mitigate Psychological Burden: By automating the detection and initial filtering of propaganda, human moderators are exposed to less harmful content, reducing the psychological toll associated with such tasks, similar to moderation of hate speech or violent content.
- Enhanced Robustness: The detector's proven ability to adapt to new topics and remain effective against attempts to change message style or omit trigger messages means moderators can rely on it to counter evolving propaganda tactics without constant retraining.
For Telegram Platform Developers:
While the paper focuses on channel-level moderation, the findings also highlight potential areas for platform-level improvements:
- Consider Data Access: The limitations imposed by Telegram's API on accessing account network information or message engagement metrics (like upvotes/downvotes) hinder the development of certain advanced detection methods. While privacy is paramount, exploring privacy-preserving ways to provide aggregated, anonymized data could foster more comprehensive research and platform-wide solutions.
- Integrate Tools: Telegram could consider offering native, platform-supported tools that incorporate mechanisms like Trigger-Propaganda embeddings directly into moderation interfaces, making them more accessible and easier to deploy for all channel owners.
For Users:
While the primary defense is automated, user awareness remains a critical layer:
- Educate on Propaganda Traits: Users can be educated about the common characteristics of propaganda accounts identified in this study—such as random/Western-looking usernames, replies lacking direct connection to trigger messages, and repeated generic content. Increased awareness can help users discern propaganda from legitimate discourse.
- Critical Thinking: The finding that propaganda messages attract replies at the same rate as legitimate user messages underscores the need for users to engage with content critically, regardless of its source or initial appearance.
For the Security Research Community:
- Expand Focus Beyond Western Platforms: This paper strongly advocates for broadening research attention beyond Western-centric social networks to address information-based attacks in instant messaging platforms globally, particularly in regions where they are primary information sources.
- Generalization and Pervasiveness Studies: Future work should explore the generalizability of this detection method to other propaganda campaigns on Telegram (e.g., non-political, commercial spam) and conduct large-scale studies to quantify the pervasiveness of propaganda activity across the entire Telegram ecosystem.
In conclusion, the Trigger-Propaganda embeddings detector provides a powerful and practical defense against sophisticated information-based attacks on Telegram, offering a faster, cheaper, and more effective solution than manual moderation, thereby significantly reducing the impact of propaganda on users and public discourse.
Key Takeaways
- Telegram's unique chronological feed and decentralized moderation model make it a challenging environment for combating information-based attacks, placing the burden largely on channel administrators with limited tools.
- The research identified two independent, coordinated propaganda networks (pro-Russian and pro-Ukrainian) on Telegram, demonstrating sophisticated operations that actively engage users and adapt narratives.
- Propaganda accounts exhibit distinct behaviors, including reactivity (only replying to messages), use of random or Western-style usernames, generic and "unlinked" replies, short lifespans despite high activity, and multi-channel participation.
- The novel Trigger-Propaganda embeddings detection mechanism, which analyzes the combined textual relationship between a legitimate user's message and a propaganda account's reply, achieved superior performance.
- This automated detector significantly outperforms human moderators, boasting a 97.4% accuracy rate (11.6 percentage points higher) and offering near real-time detection, making it faster and more cost-effective.
- The detection method is robust against evolving propaganda topics and even deliberate evasion attempts, such as changing message style with LLMs or sending messages without explicit triggers, ensuring its long-term effectiveness.
About the Speaker(s)
The research paper "Characterizing and Detecting Propaganda-Spreading Accounts on Telegram" was authored by a collaborative team of researchers from various esteemed institutions.
Klim Kireev is affiliated with the MPI-SP Max Plank Institute for Security and Privacy. His work, as demonstrated by this paper, focuses on understanding and mitigating information-based attacks on social media platforms, particularly in contexts with unique security and privacy challenges.
Yevhen Mykhno is listed as an unaffiliated researcher, indicating independent contributions to this critical study.
Carmela Troncoso holds positions at both the MPI-SP Max Plank Institute for Security and Privacy and EPFL. Her expertise lies in privacy-enhancing technologies and security, with a strong focus on data analysis and user privacy in digital communications, which is highly relevant to the ethical considerations of social media research.
Rebekah Overdorf is affiliated with the University of Lausanne, Ruhr University Bochum (RUB), the Research Center Trustworthy Data Science, and Security in University Alliance Ruhr. Her diverse affiliations suggest a broad research interest in data science, security, and trustworthy systems, crucial for analyzing complex social phenomena like propaganda dissemination.
Collectively, the authors bring a robust interdisciplinary background in security, privacy, data science, and social media analysis, enabling a comprehensive approach to tackling the complex problem of propaganda detection on platforms like Telegram.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid measurement study with a genuinely useful detection contribution. The trigger-propaganda embedding approach is clever—exploiting the semantic mismatch between legitimate messages and generic propaganda replies is a novel angle that actually works. 97% detection beating human moderators by 11 points is the kind of result that matters.
Heather Calloway (CISO) — SOLID
Solid research that delivers an actionable detection mechanism for propaganda accounts on Telegram, with 97%+ accuracy and demonstrated robustness to evasion. Worth your time if you're responsible for threat intel, brand protection, or executive communications risk on messaging platforms.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)