{"id":5136,"date":"2024-09-04T08:00:00","date_gmt":"2024-09-04T13:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/ceo-arrest-cybercriminal-interest-telegram"},"modified":"2024-09-04T08:00:00","modified_gmt":"2024-09-04T13:00:00","slug":"ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/04\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram\/","title":{"rendered":"CEO&#8217;s Arrest Will Likely Not Dampen Cybercriminal Interest in Telegram"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltabb2a13a6574290d\/66d772d548774c157121fbcd\/pavel_bella1105_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The recent arrest and indictment of Telegram CEO Pavel Durov in France will likely have little short-term impact on use of the platform among cybercriminals and nation-state backed hacking groups.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the past few years, Telegram has emerged as a haven for bad actors to communicate with each other, sell personal information, unload credit card details and user credentials, and for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/evil-telegram-spyware-campaign-infects-60k-mobile-users\" rel=\"noopener\">malware distribution<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Many also use the platform for command and control (C2), to manage botnets, to communicate with ransomware victims, to coordinate attacks, and generally as an alternative to the Dark Web.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a report earlier this year, Guardio described Telegram as playing a large role in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/labs.guard.io\/scammers-paradise-exploring-telegrams-dark-markets-breeding-ground-for-modern-phishing-a2225e51898e\" rel=\"noopener\">democratizing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> phishing operations. &#8220;This messaging app has transformed into a bustling hub where seasoned cybercriminals and newcomers alike exchange illicit tools and insights creating a dark and well-oiled supply chain of tools and victims&#8217; data,&#8221; Guardio had noted. &#8220;Free samples, tutorials, kits, even hackers-for-hire \u2014 everything needed to construct a complete end-to-end malicious campaign.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security researchers expect little will change following Durov&#8217;s arrest on charges related to bad actors using his platform for child abuse, drug traffic and for other nefarious activities. French authorities have also charged Russia-born Durov \u2014 who is now a French citizen \u2014 with not responding to law-enforcement requests for Telegram&#8217;s assistance in bringing to justice criminals who are using the platform for illicit and illegal activity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While this could lead to Telegram &#8220;cleaning house&#8221; of malicious elements, it may not move the needle on cybercrime activity, experts say.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Little Short-Term Impact on Cybercrime\">Little Short-Term Impact on Cybercrime<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Durov&#8217;s Aug. 24 arrest has been controversial and triggered considerable <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nytimes.com\/2024\/08\/25\/technology\/pavel-durov-telegram-detained-france.html\" rel=\"noopener\">debate over free speech<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> issues and the extent to which CEOs like Durov should be held liable for the behavior of users on their platforms. French President Emmanuel Macron himself has stressed Durvo&#8217;s arrest and subsequent indictment are not an attack on free speech.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;France is deeply committed to freedom of expression and communication, to innovation, and to the spirit of entrepreneurship,&#8221; Macron <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/EmmanuelMacron\/status\/1828077245606342672\" rel=\"noopener\">said in a post on X<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, formerly known as Twitter. &#8220;The arrest of the president of Telegram on French soil took place as part of an ongoing judicial investigation. It is in no way a political decision.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Durov is currently out on a roughly $5.5 million bond but cannot leave France. He is required to report twice a week to a French court.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the meantime, crackdown or not, criminals <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/lockbit-leak-site-reemerges-week-after-complete-compromise-\" rel=\"noopener\">tend to adapt quickly to changing circumstances<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and may simply increase their operational security measures while continuing to leverage the platform.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The impact of the CEO&#8217;s arrest on cybercriminal use of&nbsp;Telegram&nbsp;will likely be minimal in the short term,&#8221; says Stephen Kowski, field CTO at SlashNext Email Security+. &#8220;However, if the arrest leads to increased scrutiny or changes in&nbsp;Telegram&#8217;s policies, we could see a gradual shift to alternative communication channels.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Adam Gavish, co-founder and CEO at DoControl, notes that Telegram innately provides OpSec for users, for a few key reasons.<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\"> <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, it offers end-to-end encryption and self-destructing messages, which provide a sense of security and anonymity. Second, it allows large file transfers, making it easy to share stolen data. And third, its channel and group features let cybercriminals easily broadcast messages to many followers or collaborate in private groups. Telegram itself says it can <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/telegram.org\/faq#:~:text=Since%20Telegram%20groups%20can%20have,these%20communities%20prosper%20in%20peace.\" rel=\"noopener\">support group sizes of 200,000<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> members, which is larger than what many other social media platforms allow. The fact that users can sign up for the service with just a virtual phone number is another major bonus for threat actors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;Cybercriminals are also disincentivized from moving shop. &#8220;While there are other platforms cybercriminals could use,&nbsp;Telegram&nbsp;has reached a critical mass in terms of adoption,&#8221; Gavish says. &#8220;It&#8217;s become a go-to marketplace for buying and selling stolen data, sharing hacking tools, and coordinating attacks. Cybercriminals have established extensive networks there, so moving to a new platform would be disruptive.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One situation where criminals might be forced to seek alternate channels is if it turns out that the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/telegram-agrees-to-register-messaging-app-with-russia\" rel=\"noopener\">Russian government<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> has some sort of a backdoor to snoop on messages traversing the platform, says Rik Turner, an analyst at Omdia. In that case, fears that Durov could be pressured into revealing that backdoor to Western intelligence services, in exchange for a lighter sentence, could prompt quite a few people to seek alternative channels, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Gavish agrees that the arrest could make a small set cybercriminals more cautious about using&nbsp;Telegram for high-stakes operations. &#8220;But a mass exodus is unlikely unless we see concrete evidence that&nbsp;Telegram&#8217;s security has been compromised,&#8221; he stresses.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/ceo-arrest-cybercriminal-interest-telegram\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent arrest and indictment of Telegram CEO Pavel Durov<\/p>\n","protected":false},"author":12,"featured_media":5137,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ceos-arrest-will-likely-not-dampen-cybercriminal-interest-in-telegram.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5136"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5136\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5137"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}