Version 2 Limited

The Shift of Cybercrime to Telegram

The Great Cybercrime Migration: Why Threat Actors Are Flocking to Telegram

Executive Summary: The digital underground is undergoing a massive relocation. According to recent research by NordLayer Intelligence (powered by NordStellar), the average share of cybercrime discussions occurring on Telegram surged to 45% in the first five months of 2026—a stark 61% increase from its 28% average in 2025. This shift points to an incoming wave of high-volume, easily scalable attacks driven by lower-skilled operators.

Understanding the Research Scope

To quantify this shift, NordLayer Intelligence analyzed post volumes across monitored dark web forums and Telegram channels between January 2024 and May 2026. The research focused on seven prominent cybercrime categories: malicious AI tools, deepfakes, ransomware-as-a-service (RaaS), stealers, DDoS, malware, and phishing. The reported 45% figure is an unweighted average of Telegram’s market share across these seven distinct categories, rather than a raw percentage of all posts combined. It is important to note that this data tracks discussion volume and chatter, not confirmed attacks or victim counts, and is limited to the sources actively monitored by the platform.

What is Driving the Shift to Telegram?

Vakaris Noreika, a Cybersecurity Expert at NordLayer Intelligence, points to two primary catalysts fueling this migration:

1. The Destabilization of the Dark Web

Aggressive and highly successful law enforcement takedowns of massive hacker forums (such as LeakBase) have severely disrupted the dark web ecosystem. Building a trustworthy reputation on these forums takes years. When authorities seize a platform, the community fragments, and established sellers are forced to rebuild their credibility from scratch on smaller, unverified forums.
“Building credibility… requires time and effort, and with the increasing likelihood of it eventually getting shut down, some threat actors might deem the investment no longer worthwhile. Telegram operates without these complex re-registration and reputation-building processes, so it becomes the simpler alternative,” explains Noreika.

2. Removing Technical Friction

Accessing dark web forums requires specialized software, specific technical know-how, and often exclusive invitations. Telegram, conversely, is a mainstream messaging app available on any smartphone. This frictionless environment makes it incredibly appealing to novice threat actors looking to enter the cybercrime space. Even though Telegram reported blocking over 20 million illicit groups and channels this year, criminals can spin up new channels on the app much faster than they could rebuild compromised dark web infrastructure.

A Bifurcated Threat Ecosystem

Despite Telegram’s explosive growth, the dark web isn’t dead—it is simply evolving. The threat landscape is fracturing into two distinct tiers:
  • Telegram for the Masses: The app is heavily populated by newcomers looking for automated, plug-and-play tools to launch mass-volume attacks. Veteran hackers also use Telegram, but primarily as a marketing channel to advertise their services.
  • The Dark Web for Elite Operations: High-value, highly sensitive transactions remain firmly rooted in the dark web. The superior operational security and established vetting infrastructure of traditional darknets are necessary for high-stakes deals, as sophisticated actors are hesitant to conduct risky business on a mainstream platform that cooperates with law enforcement.

What This Means for Enterprise Security Teams

A spike in Telegram chatter does not mean adversaries are becoming more sophisticated. Rather, it indicates a massive influx of low-skill threat actors utilizing highly accessible, automated tools. IT departments should brace for a surge in easily scalable, “spray and pray” attacks, including:
  • Phishing and credential theft
  • Automated account takeover attempts
  • Denial-of-Service (DDoS) for hire
  • Deepfake-enabled social engineering fraud

Actionable Steps to Reduce Exposure

To defend against this rising tide of automated attacks, organizations must adhere to foundational cybersecurity practices recommended by CISA:
  • Deploy Phishing-Resistant MFA: Implement robust multi-factor authentication (such as hardware security keys or passkeys). Phishing-resistant MFA can neutralize over 99% of identity-based attacks, rendering stolen passwords useless.
  • Enforce Strict Password Hygiene: Mandate unique, complex passwords stored securely within a reputable enterprise password manager.
  • Automate Patch Management: Keep operating systems and applications continuously updated. For the sixth consecutive year, vulnerability exploitation remains the most common initial infection vector.
  • Minimize Digital Footprints: Restrict publicly available corporate data and audit privacy settings to reduce the raw material available for deepfake generation and targeted social engineering.
  • Leverage Dark Web Monitoring: Time is critical when credentials leak. Continuous monitoring across both the dark web and Telegram can provide early warnings, allowing security teams to force password resets and revoke access before an attacker can act.
Data Limitations & Methodology: The data spans January 2024 to May 2026, monitoring a fluctuating pool of 86 dark web forums and 1,890 Telegram channels. Year-over-year comparisons reflect both behavioral shifts and changes in the active source pool (due to platform shutdowns). Post counts measure discussion volume only and do not confirm criminal activity. This analysis describes aggregate patterns and does not constitute legal or professional security advice. References to third-party platforms are for factual reporting only.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Exit mobile version