"No, I Can't Be a Security Personnel on Your Phone": Security and Privacy Threats From Sharing Infrastructure in Rural Ghana
Emmanuel Tweneboah
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Social Issues and Security
Overview
This article delves into the critical findings presented in the USENIX Security paper "DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram." The research, conducted by Sayak Saha Roy, Elham Pourabbas Vafa, Kobra Khanmohamaddi, and Shirin Nilizadeh, uncovers the burgeoning threat posed by Cybercriminal Activity Channels (CACs) on Telegram, a platform increasingly favored by malicious actors due to its vast user base and perceived lax content moderation. The paper provides the first large-scale, systematic analysis of these broadcast-style channels, which collectively cater to over 23.8 million users, distributing a wide array of illicit content ranging from compromised credentials to sophisticated blackhat hacking tools.
Read the paper · Download the PDF (PDF) · Slides
Paper abstract
We present the first large-scale analysis of 339 cybercriminal activity channels (CACs). Followed by over 23.8M users, these broadcast-style channels share a wide array of malicious and unethical content with their subscribers, including compromised credentials, pirated software and media, social media manipulation tools, and blackhat hacking resources such as malware and exploit kits, and social engineering scams. To evaluate these channels, we developed DarkGram—a BERT-based framework that automatically identifies malicious posts from the CACs with an accuracy of 96%. Using DarkGram, we conducted a quantitative analysis of 53,605 posts posted on these channels between February and May 2024, revealing key characteristics of shared content. While much of this content is distributed for free, channel administrators frequently employ strategies, such as promotions and giveaways, to engage users and boost the sales of premium cybercriminal content. Interestingly, sometimes, these channels pose significant risks to their own subscribers. Notably, 28.1% of the links shared in these channels contained phishing attacks, and 38% of executable files were bundled with malware. Looking closely into how subscribers consume and react positively to the shared content paints a dangerous picture of the perpetuation of cybercriminal content at scale. We also found that the CACs can evade scrutiny or platform takedowns by quickly migrating to new channels with minimal subscriber loss, highlighting the resilience of this ecosystem. To counteract this, we utilized DarkGram to detect emerging channels and reported malicious content to Telegram and the affected organizations. This resulted in the takedown of 196 channels over the course of three months. Our findings underscore the urgent need for coordinated efforts to combat the growing threats posed by these channels. To aid this effort, we open-source our dataset and the DarkGram framework.

DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram
Speakers: Sayak Saha Roy (The University of Texas at Arlington); Elham Pourabbas Vafa (The University of Texas at Arlington); Kobra Khanmohamaddi (Sheridan College); Shirin Nilizadeh (The University of Texas at Arlington)
Conference: USENIX Security
YouTube: N/A - Paper Only
Paper Page: https://www.usenix.org/conference/usenixsecurity25/presentation/roy
Overview
This article delves into the critical findings presented in the USENIX Security paper "DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram." The research, conducted by Sayak Saha Roy, Elham Pourabbas Vafa, Kobra Khanmohamaddi, and Shirin Nilizadeh, uncovers the burgeoning threat posed by Cybercriminal Activity Channels (CACs) on Telegram, a platform increasingly favored by malicious actors due to its vast user base and perceived lax content moderation. The paper provides the first large-scale, systematic analysis of these broadcast-style channels, which collectively cater to over 23.8 million users, distributing a wide array of illicit content ranging from compromised credentials to sophisticated blackhat hacking tools.
The significance of this work lies in its comprehensive characterization of the Telegram cybercrime ecosystem, highlighting its unique operational dynamics compared to traditional underground forums. The authors introduce DarkGram, a BERT-based framework designed to automatically identify malicious posts with high accuracy, enabling large-scale quantitative analysis and proactive threat detection. Beyond merely cataloging malicious activities, the research critically examines the inherent risks these channels pose not only to external targets but also to their own subscribers, revealing alarming rates of phishing and malware distribution within supposedly "trusted" communities.
Ultimately, this study underscores the urgent necessity for coordinated defensive strategies against this rapidly evolving threat landscape. The paper not only provides invaluable insights for cybersecurity researchers and practitioners but also offers a practical tool in DarkGram and an open-sourced dataset to aid ongoing efforts to combat cybercrime on Telegram and similar platforms. The researchers' proactive reporting efforts, facilitated by DarkGram, led to the takedown of 196 emerging CACs, demonstrating the framework's tangible impact in disrupting these resilient cybercriminal operations.
Background
Underground online forums have historically served as primary conduits for cybercriminal activities, facilitating the exchange of resources for social engineering scams, malware attacks, credential sharing, and hacking tools. These forums, often characterized by hierarchical structures and exclusive memberships, have faced increasing scrutiny and takedown efforts from law enforcement and security vendors, particularly those operating on the clear web. This heightened pressure has prompted a significant migration of cybercriminal operations to alternative, more dynamic platforms, with social media emerging as a new frontier for exploiting vast user bases while evading traditional security measures.
Telegram, with its expansive user base of over 700 million monthly active users and a reputation for lax content moderation policies, has become a particularly attractive ecosystem for cybercriminals. Unlike dark web forums that necessitate specialized software and technical expertise, Telegram channels are often publicly accessible, significantly lowering the barrier of entry for aspiring malicious actors and those seeking illicit tools and resources. This accessibility enables the large-scale, broadcast-style distribution of illegal content, mirroring the functionalities of traditional forums but with a broader reach and simpler user experience.
Prior research has extensively documented cybercriminal activities on various online platforms, including the dark web and conventional social media. However, a comprehensive, large-scale analysis specifically focusing on the unique characteristics and operational models of dedicated cybercriminal activity channels on Telegram has been lacking. This gap motivated the present study, which aims to provide a foundational understanding of this evolving threat landscape, including the types of content shared, user engagement patterns, and the resilience mechanisms employed by these CACs. The research also contextualizes these findings against existing literature on traditional cybercriminal forums, highlighting both similarities and critical differences that underscore Telegram's distinct role in the modern cybercrime ecosystem.
Key Findings
The research presents a multi-faceted analysis of Cybercriminal Activity Channels (CACs) on Telegram, revealing critical insights into their operations, content, and impact. The study monitored 339 distinct CACs, which collectively boasted over 23.8 million subscribers, demonstrating the immense scale and reach of this cybercriminal ecosystem. These channels were categorized into five primary types: Compromised user credentials, Pirated software, Pirated media, Social media manipulation tools, and Blackhat hacking resources.
A central contribution is the development of DarkGram, a BERT-based framework capable of automatically detecting malicious posts within CACs with an impressive average accuracy of 96%. Utilizing DarkGram, the researchers analyzed 53,605 posts made between February and May 2024, identifying key characteristics of shared content and distribution strategies, including direct file uploads, external links, and interactions with Telegram bots.
A particularly alarming finding pertains to the significant risks CACs pose to their own subscribers. The analysis revealed that 28.1% of the links shared in these channels contained phishing attacks, and a staggering 38% of executable files were bundled with malware. Despite these inherent dangers, user engagement with malicious content remained predominantly positive, with approximately 78% of emoji reactions expressing approval, suggesting a widespread lack of awareness among subscribers regarding the true nature of the content.
The study also quantified the financial damage attributable to pirated software distributed via these channels. Assuming a conservative 10% conversion rate from views to actual downloads, the estimated losses to legitimate developers exceeded $40 million. Furthermore, the research highlighted the remarkable resilience of CACs against takedown efforts. When faced with removal, channels demonstrated rapid migration strategies, with a median of 43.8% of followers transitioning to new channels within a week, underscoring the limitations of current moderation approaches.
Finally, the proactive application of DarkGram led to tangible successes in disrupting these operations. By identifying and reporting newly emerging CACs, the framework facilitated the takedown of 196 channels over three months. This demonstrated DarkGram's efficacy in combating the proliferation of cybercriminal content, especially against newer channels that Telegram appears more willing to moderate compared to established ones.
Technical Deep Dive
The research behind DarkGram involved a rigorous methodology for data collection, automated detection, and in-depth analysis of cybercriminal activities on Telegram. The core technical contribution is the DarkGram framework, a sophisticated BERT-based multi-class classifier designed to automatically identify and categorize malicious posts.
Data Collection and Pre-processing:
The initial dataset of 339 Cybercriminal Activity Channels (CACs) was compiled using Telemetr.io, a third-party catalog of public Telegram channels. This platform's advanced search capabilities, keyword-based crawling, and tracking of publicly available metadata allowed the researchers to identify 4,709 English-based channels with over 10,000 followers. Two independent coders manually reviewed each channel's description and its ten latest posts, aligning criteria with the FBI's Internet Crime Report (2023) to identify malicious activities. This led to the selection of 339 channels, which were then streamlined into five distinct categories: Credential Compromise, Pirated Software, Blackhat Resources, Pirated Media, and Social Media Manipulation.
Using the official Telegram API, 64,801 posts were collected from these 339 channels between February 21st and May 29th, 2024. The API was queried at 10-minute intervals to capture new posts, subscriber counts, post views, forwards, emoji reactions, and reply content. This frequent data refresh ensured the analysis was based on the most current engagement metrics.
DarkGram Framework Design and Training:
To overcome the impracticality of manually analyzing 64,801 posts, the researchers developed DarkGram. A random sample of 10 posts from each of the 339 channels (totaling 3,390 posts) was manually labeled by two graduate students in Computer Science, achieving a Cohen’s Kappa interrater agreement of 0.78. Of these, 3,098 posts were confirmed to distribute cybercriminal content and served as true labels for training. For false labels, an equal number of benign posts were sampled from the Pushshift Telegram dataset (over 317 million messages from 27.8K channels) and manually verified.
DarkGram is built upon a BERT-base model, chosen for its demonstrated excellence in text classification tasks and its ability to capture nuanced patterns and contextual relationships within text. The model was trained on a 70:30 training-test split of the labeled dataset, achieving an initial F1-score of 98.4%. For further evaluation, an additional 2,000 randomly selected posts (1,000 positive, 1,000 benign) were manually labeled, confirming an overall F1-score of 97.8% for DarkGram. While performance was high across most categories, the Pirated Software category showed slightly lower performance (F1-score of 88.7%), likely due to the high percentage of posts (32%) lacking descriptive text and relying solely on file attachments. The decision to use BERT over commercial LLMs like ChatGPT was driven by concerns regarding data privacy, API costs, and processing speed.
Content Characterization and Harm Analysis:
For credential compromise channels, spaCy’s tokenization was used to identify key phrases in post content and filenames, accurately distinguishing between compromised user credentials and session cookies. A Selenium-based crawler was deployed to interact with external links, extracting webpage titles and invoking file downloads (without saving files for ethical reasons) to analyze hosted payloads. Bot interactions were also identified, where users were directed to contact specific bots or users for full access to leaks.
In pirated software channels, the GPT-4 API was utilized for automated categorization of software based on post text and filenames into 19 distinct categories, with 99.4% accuracy on a validation sample. GPT-4 also estimated the financial value of pirated software, categorizing them into freemium and premium models. For blackhat resources, manual review was complemented by GPT-4 to confirm content categorization.
To assess harm to subscribers, all 13,726 URLs shared in CACs were scanned with VirusTotal (flagged if detected by 2+ engines) and then by PhishIntention, a deep learning model for phishing detection, identifying a total of 3,857 malicious URLs. Executable files (3,205, primarily from pirated software and blackhat resource channels) were analyzed using Hybrid Analysis and VirusTotal, deeming a file malicious if detected by Hybrid Analysis and 2+ antivirus scanners. This process identified 1,210 malicious files, with 83 malicious Android APKs having corresponding entries on the Google Play Store, indicating distribution of repackaged or malicious apps.
Engagement Analysis:
User engagement was analyzed through metrics such as subscriber growth, post forwards, and emoji reactions. Statistical analysis confirmed that channels sharing "proofs" and samples exhibited significantly higher subscriber growth within a week. Post forwarding was identified as a critical driver, with channels experiencing over 100 forwards showing a median growth rate of 27.4% compared to 12.1% for channels with fewer forwards. Emoji reactions, predominantly positive (e.g., "Like," "Love"), indicated high approval of content, even for posts distributing malicious files or phishing links, underscoring subscribers' lack of awareness regarding risks.
Demo / Proof of Concept
While this research is presented as a peer-reviewed paper rather than a live demonstration at a conference, the authors effectively present a proof-of-concept for the DarkGram framework by deploying it in a real-time detection and reporting scenario. This practical application showcases DarkGram's capability to proactively identify and disrupt emerging Cybercriminal Activity Channels (CACs).
The real-time deployment of DarkGram involved extending its functionality to continuously monitor for new CACs on both Telegram and Facebook between May 26 and August 11, 2024. For Telegram, DarkGram searched for t.me links shared within the existing 339 ground-truth CACs, leveraging the observed behavior of cybercriminals promoting alternate or similar channels. For each identified t.me link, DarkGram analyzed the ten most recent posts, mirroring the methodology used to build the initial dataset. A channel was flagged as malicious if DarkGram identified five or more malicious posts, a threshold established to minimize false positives while ensuring consistent malicious behavior.
This proactive monitoring led to the identification of 127 new malicious Telegram channels out of 245 examined links. To demonstrate its cross-platform applicability, DarkGram was also run on Facebook, utilizing the CrowdTangle API (now Meta Content Library) to extract t.me links embedded in posts from public groups. This resulted in the flagging of 69 malicious channels (shared across 14 Facebook groups) from 4,191 links. In total, DarkGram identified 196 new CACs.
The effectiveness of this proof-of-concept was further validated by the subsequent takedown efforts. DarkGram automatically reported these newly identified channels to Telegram's abuse email, providing detailed evidence including channel names, URLs, descriptions, and summaries of malicious posts. This evidence-based reporting proved highly effective, leading to the removal of all 196 reported channels with a median response time of just four days. This outcome stands in stark contrast to the lower removal rate observed for older, more established channels (only 64 out of 339 original CACs were removed), highlighting the critical importance of early detection. The research also reported 597 malicious URLs and 314 files, resulting in the removal of 343 URLs, with 157 confirmed by domain providers as a direct result of the reports. This real-world application of DarkGram serves as a compelling demonstration of its potential to significantly impact the fight against cybercrime on Telegram and other social media platforms.
Defensive Implications
The findings from the DarkGram research present critical defensive implications for various stakeholders, including platform providers, security vendors, and end-users. The insights gained underscore the urgent need for a multi-pronged approach to combat the growing threat of Cybercriminal Activity Channels (CACs) on Telegram.
For Telegram and other Social Media Platforms:
The study reveals significant shortcomings in Telegram's existing content moderation policies, particularly concerning established CACs. The platform's apparent reluctance to remove older, more popular channels, coupled with its heavy reliance on user reporting, allows cybercriminal ecosystems to flourish. Telegram must implement more proactive and stringent moderation mechanisms, potentially integrating automated detection frameworks like DarkGram. Addressing the resilience strategies of CACs, such as rapid channel migration and content concealment behind bots, is paramount. This requires developing more sophisticated detection algorithms that track content and communities rather than just individual channels, and enforcing stricter policies against channels that facilitate these evasion tactics.
For Cybersecurity Researchers and Security Vendors:
The open-sourced dataset and the DarkGram framework provide invaluable resources for ongoing research and threat intelligence. Security vendors can leverage DarkGram to enhance their own detection capabilities for malicious content originating from Telegram. Proactive monitoring of CACs can help identify emerging threats, compromise indicators (e.g., newly leaked credentials), and new malware strains. The observed overlap between Telegram CACs and traditional cybercriminal forums suggests that threat intelligence efforts should integrate data from both ecosystems to gain a more comprehensive view of the cybercrime landscape. Furthermore, collaborating with affected organizations to report compromised credentials and malicious infrastructure identified on Telegram is crucial for timely mitigation.
For End-Users and the Public:
The research highlights a critical vulnerability: subscriber unawareness. The predominantly positive reactions to posts containing phishing links and malware underscore the need for enhanced user education. Users, especially those seeking pirated software, media, or social media manipulation services, are prime targets for scams and should exercise extreme caution. They must be educated about the inherent risks of clicking unverified links, downloading executables from unofficial sources, and engaging with content that promises illicit gains or free access to paid services. A healthy skepticism towards "proofs," giveaways, and offers that seem too good to be true is essential. It is also important for users to understand that even within seemingly "safe" platforms like Telegram, malicious actors operate and can exploit trust for their own gain.
For Law Enforcement and Policy Makers:
The study provides concrete evidence of the scale and sophistication of cybercriminal operations on Telegram. This information can inform policy decisions regarding platform accountability for content moderation. Coordinated international efforts are necessary to address the cross-border nature of these cybercriminal networks and to pressure platforms to adopt more robust security measures. The financial damage estimates underscore the economic impact of these activities, further justifying increased investment in cybersecurity research and enforcement.
In summary, combating the threats posed by Telegram CACs requires a collaborative and multi-faceted approach. By leveraging advanced detection tools, improving platform moderation, enhancing user awareness, and fostering inter-organizational cooperation, defenders can collectively work towards disrupting this resilient and dangerous cybercriminal ecosystem.
Key Takeaways
- Telegram has become a significant hub for large-scale cybercriminal activity, hosting 339 dedicated Cybercriminal Activity Channels (CACs) with over 23.8 million subscribers distributing compromised credentials, pirated content, social media manipulation tools, and blackhat hacking resources.
- Subscribers to CACs face substantial direct risks, with 28.1% of shared links leading to phishing attacks and 38% of executable files containing malware, often without their awareness, as evidenced by overwhelmingly positive user reactions.
- The DarkGram framework, a BERT-based classifier, effectively detects malicious posts with 96% accuracy and has proven instrumental in proactively identifying and facilitating the takedown of 196 newly emerging CACs.
- CACs exhibit remarkable resilience to takedown efforts, rapidly migrating followers (median 43.8% transition within a week) to new channels, and often hosting content directly on Telegram or concealing it behind bots, making traditional moderation challenging.
- Lax content moderation policies on Telegram enable the proliferation of cybercrime, particularly for established channels, highlighting the urgent need for platforms to implement more proactive detection and enforcement mechanisms.
- Sophisticated monetization and trust-building strategies are employed by CACs, including sharing "proofs," offering giveaways, and utilizing bots for sales, which effectively engage users and attract new subscribers, contributing to the ecosystem's growth.
About the Speaker(s)
The research paper "DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram" was authored by a collaborative team of researchers: Sayak Saha Roy, Elham Pourabbas Vafa, and Shirin Nilizadeh from The University of Texas at Arlington, and Kobra Khanmohamaddi from Sheridan College. Their collective expertise spans critical areas of computer science and security. Sayak Saha Roy and Elham Pourabbas Vafa are affiliated with the University of Texas at Arlington, where they likely contribute to research in cybersecurity and related fields. Shirin Nilizadeh, also from The University of Texas at Arlington, brings a strong background in computer security and social computing, which is evident in the paper's focus on user behavior and platform dynamics. Kobra Khanmohamaddi from Sheridan College further strengthens the team with a background in computer security. Their combined academic and research experience was crucial in conducting this comprehensive, multi-faceted analysis of cybercriminal activity on Telegram, utilizing advanced machine learning techniques and rigorous data analysis methodologies.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Solid measurement paper that does the boring-but-necessary work of systematically cataloging Telegram's cybercrime ecosystem. The 339-channel dataset and BERT classifier are genuinely useful contributions. Not revolutionary, but the 28% phishing rate and 38% malware-in-executables numbers are concrete data points defenders can actually cite.
Heather Calloway (CISO) — SOLID
Solid threat intelligence work that quantifies a platform shift every security program should be tracking. The 23.8 million subscriber footprint, 28% phishing rate in shared links, and 38% malware rate in executables are numbers I'd put in front of my risk committee. This changes how we think about threat intel sourcing and employee exposure on consumer messaging platforms.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)