Cybercrime moves into the mainstream: Why threat actors are increasingly turning to Telegram | #cybercrime | #infosec


For years, the dark web has served as the digital underworld’s marketplace, where cybercriminals buy and sell stolen credentials, trade malware, advertise ransomware services, and exchange techniques for evading law enforcement. Today, however, a notable shift appears to be underway. New research suggests that a growing proportion of cybercrime-related discussions are taking place on Telegram, a mainstream messaging platform used by hundreds of millions of people worldwide.

According to analysis conducted by NordLayer Intelligence by NordStellar, Telegram’s share of cybercrime discussions across seven monitored cybercrime categories reached 45 percent during the first five months of 2026, compared with 28 percent across the entirety of 2025. This represents a 61 percent increase in just over a year.  While this does not mean that cybercrime itself has moved entirely away from the dark web, it does indicate a significant change in how threat actors communicate, collaborate, and recruit.

The decline of the traditional cybercrime forum?

The findings emerge against a backdrop of increasing law enforcement pressure on dark web communities. Major forum takedowns and seizures have disrupted criminal ecosystems that took years to establish. One example cited by NordLayer Intelligence is the seizure of the hacker forum LeakBase, which reportedly contributed to the fragmentation of established cybercrime networks.

According to cybersecurity expert Vakaris Noreika of NordLayer Intelligence, dark web forums function as communities where reputation matters. Vendors and criminal service providers often spend years building credibility before they are trusted enough to conduct significant transactions. When a forum is shut down, that reputation infrastructure can disappear overnight.  This creates uncertainty for cybercriminals. Re-establishing credibility on a new platform can be difficult, particularly when there is a growing expectation that any replacement forum may eventually be dismantled as well. Telegram, by contrast, offers a lower-friction environment that enables participants to join communities quickly and communicate without the same lengthy vetting processes. Seemingly of greater concern is what this shift could mean for the broader threat landscape.

Accessing traditional dark web forums often requires specialised software such as Tor, familiarity with underground communities, and sometimes invitations or sponsorship from existing members. These requirements can act as barriers that limit participation by inexperienced actors.  Telegram removes many of those obstacles.

As a mainstream messaging application, Telegram can be accessed through standard smartphones and computers without requiring specialist technical knowledge. According to NordLayer Intelligence, this may be helping to attract a new generation of cybercriminals seeking ready-made attack tools and automated services.  The result may not necessarily be more sophisticated cybercrime. Instead, organisations could face larger numbers of lower-skilled attackers using easily obtainable tools to launch attacks at scale. This phenomenon mirrors broader trends in cybercrime-as-a-service, where malware kits, phishing platforms, credential-stealing software, and denial-of-service capabilities can be rented or purchased with relatively little expertise required.

Deadly seven forms of cybercrime

The research examined discussions relating to seven major cybercrime categories: phishing, malware, ransomware-as-a-service, distributed denial-of-service attacks, credential-stealing software, deepfakes, and malicious artificial intelligence tools. Between January 2024 and May 2026, NordLayer Intelligence monitored 86 dark web forums and 1,890 Telegram channels to identify discussion trends.  Importantly, the researchers emphasise that discussion volume does not necessarily equate to confirmed criminal activity. Nevertheless, where cybercriminals gather and communicate often provides valuable insight into emerging threats and evolving attack methodologies.

One particularly significant development is the growing overlap between artificial intelligence and cybercrime. Recent NordLayer analysis found that discussions concerning AI tools on underground forums have increased substantially following major releases of advanced large language models, suggesting threat actors are actively exploring how emerging technologies may support criminal activities.  Combined with Telegram’s accessibility, this raises concerns about the democratisation of cybercrime, where increasingly capable attack tools become available to individuals with relatively limited technical expertise.

The attack types favoured  by criminals are attractive because they can be repeated frequently, require relatively limited resources, and can be launched against large numbers of potential victims simultaneously.  For businesses, this means that traditional cybersecurity fundamentals remain as important as ever. Strong password practices, multi-factor authentication, regular software patching, access control reviews, and employee awareness training continue to represent some of the most effective defensive measures.

Hence, the findings also reinforce the growing importance of threat intelligence and dark web monitoring. Since leaked credentials and stolen data frequently appear first within criminal communities, early detection can provide valuable time to change passwords, revoke access permissions, and investigate potential compromise before greater damage occurs.



Click Here For The Original Source.

——————————————————–

..........

.

.