The Great Cybercrime Migration: Why Threat Actors Are Flocking to Telegram
Understanding the Research Scope
To quantify this shift, NordLayer Intelligence analyzed post volumes across monitored dark web forums and Telegram channels between January 2024 and May 2026. The research focused on seven prominent cybercrime categories: malicious AI tools, deepfakes, ransomware-as-a-service (RaaS), stealers, DDoS, malware, and phishing. The reported 45% figure is an unweighted average of Telegram’s market share across these seven distinct categories, rather than a raw percentage of all posts combined. It is important to note that this data tracks discussion volume and chatter, not confirmed attacks or victim counts, and is limited to the sources actively monitored by the platform.What is Driving the Shift to Telegram?
Vakaris Noreika, a Cybersecurity Expert at NordLayer Intelligence, points to two primary catalysts fueling this migration:1. The Destabilization of the Dark Web
Aggressive and highly successful law enforcement takedowns of massive hacker forums (such as LeakBase) have severely disrupted the dark web ecosystem. Building a trustworthy reputation on these forums takes years. When authorities seize a platform, the community fragments, and established sellers are forced to rebuild their credibility from scratch on smaller, unverified forums.2. Removing Technical Friction
Accessing dark web forums requires specialized software, specific technical know-how, and often exclusive invitations. Telegram, conversely, is a mainstream messaging app available on any smartphone. This frictionless environment makes it incredibly appealing to novice threat actors looking to enter the cybercrime space. Even though Telegram reported blocking over 20 million illicit groups and channels this year, criminals can spin up new channels on the app much faster than they could rebuild compromised dark web infrastructure.A Bifurcated Threat Ecosystem
Despite Telegram’s explosive growth, the dark web isn’t dead—it is simply evolving. The threat landscape is fracturing into two distinct tiers:- Telegram for the Masses: The app is heavily populated by newcomers looking for automated, plug-and-play tools to launch mass-volume attacks. Veteran hackers also use Telegram, but primarily as a marketing channel to advertise their services.
- The Dark Web for Elite Operations: High-value, highly sensitive transactions remain firmly rooted in the dark web. The superior operational security and established vetting infrastructure of traditional darknets are necessary for high-stakes deals, as sophisticated actors are hesitant to conduct risky business on a mainstream platform that cooperates with law enforcement.
What This Means for Enterprise Security Teams
A spike in Telegram chatter does not mean adversaries are becoming more sophisticated. Rather, it indicates a massive influx of low-skill threat actors utilizing highly accessible, automated tools. IT departments should brace for a surge in easily scalable, “spray and pray” attacks, including:- Phishing and credential theft
- Automated account takeover attempts
- Denial-of-Service (DDoS) for hire
- Deepfake-enabled social engineering fraud
Actionable Steps to Reduce Exposure
To defend against this rising tide of automated attacks, organizations must adhere to foundational cybersecurity practices recommended by CISA:- Deploy Phishing-Resistant MFA: Implement robust multi-factor authentication (such as hardware security keys or passkeys). Phishing-resistant MFA can neutralize over 99% of identity-based attacks, rendering stolen passwords useless.
- Enforce Strict Password Hygiene: Mandate unique, complex passwords stored securely within a reputable enterprise password manager.
- Automate Patch Management: Keep operating systems and applications continuously updated. For the sixth consecutive year, vulnerability exploitation remains the most common initial infection vector.
- Minimize Digital Footprints: Restrict publicly available corporate data and audit privacy settings to reduce the raw material available for deepfake generation and targeted social engineering.
- Leverage Dark Web Monitoring: Time is critical when credentials leak. Continuous monitoring across both the dark web and Telegram can provide early warnings, allowing security teams to force password resets and revoke access before an attacker can act.
About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.
About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

