DEV Community

Cover image for If You Use Telegram in 2026: Read This Now
Scofield Idehen
Scofield Idehen

Posted on Originally published at catcham.xyz

If You Use Telegram in 2026: Read This Now

12 Charges. 20 Years. For Refusing to Cooperate. The rise of Telegram and how the platform harbors scammers, money launderers, and all kinds of vices, and how Pavel Durov is shielding them.

In August 2025, the tech world was shaken when  Telegram’s founder,  Pavel Durov , was arrested in France on allegations tied to the misuse of his platform. Everyone was shocked.

For years, Telegram branded itself as the go-to app for  secure, encrypted, and censorship-resistant conversations , attracting nearly a  billion global users  from political activists to everyday people who wanted privacy.

But privacy is a double-edged sword. While Telegram has given millions a safe space to communicate beyond government reach, its very features  end-to-end encryption, anonymous accounts, and bot integration  have also made it a  fertile ground for cybercriminals, scammers, and even nation-state hackers .

The app isn’t just a messenger anymore; it’s a  marketplace, a dark web alternative, a battlefield for digital warfare .

From sophisticated malware campaigns to simple but devastating social engineering scams, hackers are exploiting Telegram’s popularity at scale.

If you are an active user, you've likely come across one Telegram scam or another, and whether you've fallen victim or not, the scams are becoming more sophisticated, even bypassing users entirely.

With over 900 million users, Telegram is proving that popularity comes at a cost. Hackers, scammers, and even state-sponsored groups have turned the app into a prime hunting ground . From  Android zero-day exploits  to  social engineering scams , the platform has faced one of its most dangerous years yet.

So let’s break down some of the scams and hacks currently active and what you should do immediately after reading this.

The Zero-Click Sticker Exploit

Disclosed on March 31, 2026, by Trend Micro's Zero Day Initiative, this is the most severe Telegram vulnerability to surface in years, a critical remote-code-execution flaw triggered through animated stickers on Telegram for Android and Telegram Desktop for Linux. Italy's national cybersecurity agency put it bluntly: exploiting it "could give an attacker control over the device and access to sensitive data, including messages, contacts, and active sessions." No interaction beyond receiving the sticker is required.

Security tip: Update Telegram the moment a fix ships. Until then, if you run a Telegram Business account, restrict messages to your address book or Premium users, and consider using Telegram Web in an updated browser instead of the native app.

EvilLoader

The most alarming Telegram exploit of 2025 so far is  EvilLoader , a critical  zero-day vulnerability  that remains unpatched in Telegram for Android (v11.7.4).

The attack disguises malicious APKs as innocent  video clips shared in chats. When a victim taps the file, Telegram prompts them to “open externally.” Instead of playing a video, the malware installs silently on the device, thereby gaining access to files, messages, and even financial apps.

Because Telegram has yet to fix this flaw,  millions of users remain at risk . Cybercriminals are actively selling EvilLoader kits on underground forums, making this one of the  biggest ongoing Telegram emergencies  in 2025.

Security Tip:  Never install or run files from Telegram chats unless they come from a source you personally trust.

The 200-Million-Record Leak

On January 24, 2026, a 44GB dataset compiled from three separate databases turned up on BreachForums, over 200 million Telegram user records, including names, usernames, emails, and phone numbers. A closer look found 60 million of those records tied to a much larger pool of 16 billion exposed credentials from earlier breaches. Researchers believe it's a mix of scraped Telegram data and older stolen credentials rather than one new hack, but the effect is the same: if you're in it, phishing attempts using your real name, number, and Telegram handle just got a lot more convincing.

Security tip: Enable two-step verification now. A leaked email and phone number are only dangerous to accounts that don't also require a password Telegram never sees.

CVE-2026-94488: The Desktop Export Flaw

A high-severity (CVSS 8.2) cross-site scripting bug was found in how Telegram Desktop exports chats to HTML, affecting versions 4.15.1 through 6.9.3. The dangerous part: an attacker doesn't need to be in your group to exploit it.

Forwarding a crafted message into any group is enough to plant the payload, and it fires the moment someone exports that chat. It's fixed in 6.9.4 (fully resolved in 7.0.1).

Security tip: If you're on Desktop and haven't updated in a while, do it before you next export any conversation.

AI Is Now Doing the Convincing

This is the real shift in 2026: the trust-based scams that used to take a human real time and effort to run are now automated. Fake investment groups post AI-generated charts, testimonials, and "video proof" of payouts that never happened. Bots hold entire real-time conversations posing as customer support, a brand, or a friend, and don't break character.

Most concerning is voice cloning: a message that sounds exactly like someone you know, asking you to send money urgently, generated from a few seconds of audio scraped from anywhere online. Fake "admin" accounts, sometimes AI-run, push group members toward malicious tools using the same authority cues a real moderator would.

Security tip: Treat any urgent money request as fake until verified through a second channel, a phone call, a video call, anything that isn't the same chat the request came from. AI can clone a voice; it's much harder to fake a live back-and-forth.

Criminal Marketplaces Keep Rebuilding

Telegram's black-market channels don't stay banned. Haowang Guarantee moved over $27 billion before its 2025 shutdown, and its vendors were back in business under a new name within weeks. Every ban buys a few months, not an ending. Read how that one played out.

8. SIM-Swap Account Takeovers

Phone numbers still anchor Telegram account verification, which makes SIM-swapping one of the most reliable ways to seize a high-value account outright — channel, contacts, and all, no password required.

Security tip: Ask your carrier about SIM-swap protection or move to an eSIM where you can.

Telegram Name Scam

In April 2025, LearnHub Africa exposed a fast-growing scam: the  Telegram Name Scam .

Scammers exploit the hype around  rare Telegram usernames, short handles, and “premium” names that can be traded or sold through platforms like  Fragment . Victims are lured into “selling” or “buying” usernames but are tricked into handing over their accounts entirely.

Some scams use  phishing links , while others convince users to  transfer ownership temporarily , only for the account to be hijacked permanently. In many cases, scammers then demand a  ransom for the return.

Unlike technical hacks, this scam relies on  social engineering, manipulating human trust and greed.

Security Tip:  Never transfer your Telegram username or respond to unsolicited offers. Treat your handle as securely as your password.

Lazarus Group’s Telegram Malware Campaign

The notorious North Korean Lazarus Group has upgraded its Telegram playbook for crypto investors. Operatives now pose as employees at legitimate trading firms, message targets directly, and build a real rapport before sending a link to a fake scheduling page mimicking Calendly or PicTime.

Approving that page triggers memory-resident malware that never writes to disk, so it leaves nothing for a traditional antivirus scan to find. It's a "human-in-the-loop" attack: patient, personal, and built specifically to be invisible after the fact.
Security tip: Never approve a calendar or scheduling link from someone you only just started talking to, no matter how legitimate the conversation has felt so far.

The group’s targets include:

  • Crypto investors
  • Fintech workers
  • High-value business professionals

Lazarus has been tied to billion-dollar heists in the past, and its adoption of Telegram makes detection and takedown efforts even harder.

Security Tip:  If you handle crypto or sensitive data, use separate devices and regularly scan for malware.

Telegram Bots Weaponized by Hackers (PXA Stealer)

A Vietnamese-speaking hacking group leveraged Telegram bots to automate widespread  data theft  in 2025.

Their method:

  1. Victims were tricked into downloading fake “Word” or “PDF reader” apps.
  2. The apps carried  PXA Stealer , a malware that harvested passwords, cookies, and credit cards.
  3. Stolen data was funneled straight into  Telegram bot channels , giving attackers instant access.
  4. The credentials were resold using underground services like  Sherlock  and  Daisy Cloud .

This hack shows how criminals weaponize Telegram’s own  bot framework  for industrial-scale cybercrime.

Hikka Userbot Exploit (CVE-2025-52571)

In January 2025, researchers disclosed a major flaw in the Hikka Telegram userbot—a tool used by communities for automation.

Versions below  1.6.2  contained a vulnerability that allowed  unauthenticated attackers  to:

  • Hijack the userbot
  • Take over the linked Telegram account
  • Gain control of the server, running it

This meant that anyone running outdated Hikka bots had unknowingly given hackers the keys to their accounts and servers.

Security Tip:  If you use Telegram bots, keep them updated or shut them down if you don’t absolutely need them.

Criminal Channels Selling Malware & Phishing Kits

A 2025 academic study of 339 criminal Telegram channels revealed that Telegram has become a thriving black market for cybercrime:

  • 28% of shared links  led to phishing websites.
  • 38% of executable files  contained malware.
  • Criminals promoted their “products” with discounts, giveaways, and even customer support.

Telegram isn’t just being  attacked;  it’s also a  hub for attackers  to trade tools and recruit accomplices.

16 Billion Credentials Exposed

In June 2025, researchers discovered one of the largest leaks of login credentials ever: 16 billion usernames and passwords, stolen by  infostealer malware .

Among them were countless  Telegram accounts . Attackers could log into victims’ accounts directly—especially if two-factor authentication (2FA) wasn’t enabled.

This wasn’t a Telegram-specific hack but highlights how  third-party breaches put Telegram users at risk .

Security Tip:  Enable  two-step verification  in Telegram’s settings. Without it, your account is one stolen password away from takeover.

SIM-Swap Hijack: The Fall of VChK-OGPU Channel

In April 2025, one of Russia’s largest independent Telegram channels— VChK-OGPU, with over 1 million subscribers- was hijacked and deleted.

Hackers reportedly performed a  SIM-swap attack , cloning the phone number linked to the account. Once inside, they seized control and wiped the channel entirely.

For high-profile accounts, SIM hijacking remains one of the  biggest threats on Telegram , since phone numbers are still tied to verification.

Security Tip:  Request SIM-swap protection from your carrier or use an  eSIM  where available.

ShinyHunters’ Extortion Campaign via Telegram

The infamous hacker collective ShinyHunters used Telegram in a high-stakes extortion scheme against the UK’s Legal Aid Agency in 2025.

They stole over  two million sensitive records  and threatened to leak them unless demands were met. Telegram channels became the group’s platform of choice to publicize threats and communicate ransom details.

Even though the data wasn’t released after the deadline, this case highlighted how  Telegram doubles as a tool for cyber blackmail.

Social Engineering

While technical exploits grab headlines,  social engineering scams  are the most dangerous. They bypass firewalls and updates by targeting  human psychology .

1. Impersonation Scams

In one extreme case, a crypto investor lost  783 BTC ($91 million)  after being tricked by attackers  impersonating hardware wallet and exchange support staff . The same tactics appear on Telegram, where scammers pose as insiders or “admins.”

2. Scam Bots

Reddit users warn of bots that  phish OTPs, CVVs, and PINs  directly in Telegram. Victims are tricked into clicking and entering details in seconds.

3. Personalized Deception

Scammers now use  first names and tailored greetings  to seem credible. One Redditor noted:

“Telegram scammer mentioned my first name… profile setup looked real enough.”

Takeaway : If it feels personal, it’s engineered.

Key Takeaways in 2026

  • Technical exploits  (EvilLoader, Hikka, sticker flaws) expose vulnerabilities in the app itself.
  • Social engineering  (Telegram Name Scam) proves humans are still the weakest link.
  • Nation-state actors  (Lazarus Group) show how Telegram is part of global cyberwarfare.
  • Criminal marketplaces  thrive openly in Telegram channels.
  • SIM-swaps and extortion  demonstrate risks for both individuals and organizations.

How to Protect Yourself Right Now

  1. Enable 2FA  in Telegram → Settings → Privacy & Security → Two-Step Verification.
  2. Update frequently  to patch vulnerabilities.
  3. Beware of links, files, and stickers  from unknown contacts.
  4. Avoid username trades  or “premium handle” offers.
  5. Use unique passwords  with a password manager.
  6. Protect your SIM  by asking your carrier about SIM-swap locks.
  7. Stay informed —scammers evolve faster than platforms can patch. ##  Conclusion

Telegram’s growth has made it a global powerhouse, but  2025 proves it’s also a global target . From Lazarus Group’s cyber-espionage campaigns to everyday scams like the  Telegram Name Scam , the threats are escalating in both scale and creativity.

The lesson is clear:  Telegram is not invincible.  Security is not guaranteed—it’s something every user must actively protect.

If you’re on Telegram in 2025, the time to act is now. Update, enable 2FA, and stay vigilant—because hackers are moving faster than ever.

If you enjoyed this story, consider joining our mailing list. We share real stories, guides, and curated insights on web developmentcybersecurityblockchain, and cloud computing, no spam, just content worth your time.

Resource 

New critical Telegram zero-click issue threatens total device compromiseData leak exposes over 200M Telegram user recordsCVE-2026-94488: Telegram Desktop XSS (CVSS 8.2)Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto FirmsLazarus Group Targets Crypto Investors on Telegram With Stealthy MalwareAI-Powered Scams on WhatsApp, Instagram & Telegram (2026 Guide)Trial for Pavel Durov Set for 2026

Top comments (0)