FOGINT: Telegram Sends Message: We Are Coming to America!
January 15, 2025
A short blog post from the FOGINT team.
In 1988, Eddie Murphy starred in the film Coming to America. The film features this bit of dialogue:
- Lisa McDowell: So why did you come here?
- Prince Akeem: To find something special.
- Lisa McDowell: It’s a long way to travel.
- Prince Akeem: No journey is too great when one finds what he seeks.
What Telegram and its wing man, the Open Network Foundation, seek is a new market. Telegram, since the detainment of Pavel Durov (Telegram’s founder) has been pushing crypto. Pushing hard. Now the organization with more than 900 million users is coming to America. “No journey is too great when one finds what he seeks.” And what Pavel Durov seeks is a market for online gambling linked to crypto currency. Online gambling, link ups with organizations mostly unknown in the US, and a messaging system with a mind-boggling range of features.
Pavel Durov is coming to the New World, a land of opportunity for crypto and certain interests unlikely to be aligned with those of the United States and its allies. Thanks, creative You.com. Good enough.
Bloomberg published “Telegram Linked TON Blockchain to Expand in US As Trump Courts Crypto.” Similar stores have appeared in Cryptobriefing, Cryptotimes, and Cryptonews, among others. For example, “Telegram-Linked TON Eyeing U.S. Expansion” reports:
The TON Foundation, associated with Telegram Messenger, is planning to expand into the U.S. market, anticipating more favorable regulatory conditions under President-elect Donald Trump. As part of its U.S. expansion strategy, the foundation has appointed Manuel Stotz, founder of Kingsway Capital Partners, as its new president.
The film was a comedy. Telegram’s return to the United States is an important step. Telegram is not just a messenger service used by warfighters, purveyors of contraband, and goofy pitches for get rich schemes originating in Myanmar. Telegram is different from Signal, Threema, and WhatsApp. The decentralized organized organization has a social media component, a recruitment program, a venture fund, some smart software, and a conceptual commitment to ideas somewhat different from those in the US and some countries in Western Europe, including France where Pavel Durov is confined to the country as a legal proceeding involving him moves forward through the French judicial system.
As Prince Akeem said, “No journey is too great when one finds what he seeks.” Mr. Durov has found what he seeks. Telegram in America.
Stephen E Arnold, January 15, 2025
More about NAMER, the Bitext Smart Entity Technology
January 14, 2025
A dinobaby product! We used some smart software to fix up the grammar. The system mostly worked. Surprised? We were.
We spotted more information about the Madrid, Spain based Bitext technology firm. The company posted “Integrating Bitext NAMER with LLMs” in late December 2024. At about the same time, government authorities arrested a person known as “Broken Tooth.” In 2021, an alert for this individual was posted. His “real” name is Wan Kuok-koi, and he has been in an out of trouble for a number of years. He is alleged to be part of a criminal organization and active in a number of illegal behaviors; for example, money laundering and human trafficking. The online service Irrawady reported that Broken Tooth is “the face of Chinese investment in Myanmar.”
Broken Tooth (né Wan Kuok-koi, born in Macau) is one example of the importance of identifying entity names and relating them to individuals and the organizations with which they are affiliated. A failure to identify entities correctly can mean the difference between resolving an alleged criminal activity and a get-out-of-jail-free card. This is the specific problem that Bitext’s NAMER system addresses. Bitext says that large language models are designed for for text generation, not entity classification. Furthermore, LLMs pose some cost and computational demands which can pose problems to some organizations working within tight budget constraints. Plus, processing certain data in a cloud increases privacy and security risks.
Bitext’s solution provides an alternative way to achieve fine-grained entity identification, extraction, and tagging. Bitext’s solution combines classical natural language processing solutions solutions with large language models. Classical NLP tools, often deployable locally, complement LLMs to enhance NER performance.
NAMER excels at:
- Identifying generic names and classifying them as people, places, or organizations.
- Resolving aliases and pseudonyms.
- Differentiating similar names tied to unrelated entities.
Bitext supports over 20 languages, with additional options available on request. How does the hybrid approach function? There are two effective integration methods for Bitext NAMER with LLMs like GPT or Llama are. The first is pre-processing input. This means that entities are annotated before passing the text to the LLM, ideal for connecting entities to knowledge graphs in large systems. The second is to configure the LLM to call NAMER dynamically.
The output of the Bitext system can generate tagged entity lists and metadata for content libraries or dictionary applications. The NAMER output can integrate directly into existing controlled vocabularies, indexes, or knowledge graphs. Also, NAMER makes it possible to maintain separate files of entities for on-demand access by analysts, investigators, or other text analytics software.
By grouping name variants, Bitext NAMER streamlines search queries, enhancing document retrieval and linking entities to knowledge graphs. This creates a tailored “semantic layer” that enriches organizational systems with precision and efficiency.
For more information about the unique NAMER system, contact Bitext via the firm’s Web site at www.bitext.com.
Stephen E Arnold, January 14, 2025
FOGINT: The French Method for Communicating with Telegram Works
January 8, 2025
Direct action by French authorities has had a visible impact on Telegram. The FOGINT team noted a report in Arab News which provides some color to this observation. “Surge in Telegram User Data Passed to French Authorities.” The article reports:
Messaging service Telegram passed vastly more data on its users to French authorities in the second half of 2024 following founder Pavel Durov’s arrest in Paris, figures published by the platform showed.
The company said it handed over IP addresses or telephone numbers that Paris asked for in 210 cases in July-September and 673 in October-December.
Prior to the action by French authorities, Telegram had the reputation of ignoring legitimate requests from government authorities in the EU and elsewhere. The company explained that it stood for free speech. However, in April 2024, Telegram blocked Ukrainian government messages from Ukraine to Telegram users in Russia.
According to the article, Telegram explained:
He [Mr. Durov] and his supporters have claimed that most French and European authorities’ requests for user data were simply not being sent to the right department at the company and therefore received no response.
Several observations from the FOGINT team are warranted:
- Direct action by French authorities has been productive. Consequently Telegram has responded.
- Mr. Durov remains under observation by the French government with his legal proceedings moving at the speed of the French bureaucracy; that is, in a methodical manner.
- Mr. Durov’s releasing of user names associated with active investigations has pushed Telegram into a course change for 2025. The company is now emphasizing its crypto currency features, functions, and services.
Consequently Telegram’s technical platform and its ability to take advantage of growing interest in online gambling provide a new challenge to investigators. Its flurry of deals with crypto centric organizations in Eastern Europe and Southeast Asia pose a new challenge to investigators. Tracking financial transactions facilitated by Telegram’s global decentralized and distributed design becomes more costly and time intensive. Telegram’s smart automation allows transactions to move from crypto currency wallet to crypto currency wallet under different identities quickly. The likely use case for Telegram’s crypto services may be money laundering.
Stephen E Arnold, January 8, 2025
Dubai: The 21st Century Crypto “Silicon Valley”
January 7, 2025
Information from the FOGINT research team.
How prescient was Telegram when it selected Dubai as headquarters of a decentralized, distributed company? After Pavel Durov bounced from Moscow to Berlin, to Singapore to San Francisco, and ended up in Dubai, United Arab Emirates, his judgment seems good. FOGINT’s view is that he listened to UAE government officials and determined that that country wanted to become the financial hub for crypto currency. The goal of both UEA and Telegram aligned: Both wanted to exploit a desire of many countries and financial entrepreneurs from the US-centric financial system to one based on crypto currency, largely unregulated crypto currency cut loose from the shackles of the US financial system. A standard other than and competitive with the US dollar promised a shift of finance from Wall Street to Sheikh Zayed Road.
The plan is not a secret. “UAE to Attract Crypto Ventures Amid EU’s Stringent MiCA Regulation: Experts” reports that regulations in Western Europe are adding a kick in the pants for some crypto-centric innovators. The regulation is Markets in Crypto-Assets Regulation (MiCA). Its purpose is to establish a legal framework — that is, uniform rules for crypto assets — across the EU. MiCA might be the booster that the United Arab Emirates and other Middle Eastern states want. A more supportive regulatory environment and a thriving crypto community exist in the United Arab Emirates.
According to the Crypto News’ report:
The MiCA regulation introduces a pan-European licensing and supervisory regime for crypto-assets, exchanges, and service providers… Among its stringent requirements, small stablecoin issuers must hold 30% of their reserves in low-risk EU-based commercial banks, while major players like Tether face a mandate to maintain 60% or more in similar institutions. While aimed at ensuring market stability, these rules are seen as increasing operational costs, potentially undermining the financial viability of many firms.
The FOGINT team wants to point out that the UAE provides a “crucible” for crypto innovation; specifically:
- A regulatory environment different from that in the US and Western Europe; for example, a Virtual Assets Regulatory Authority (VARA) in Dubai oversees the regulation, licensing, and governance of virtual assets
- Tax benefits because there is currently no direct taxation on cryptocurrencies in the UAE
- Infrastructure provides a “Silicon Valley”-type of magnetic pull situated almost equidistant from Asian financial hubs and Western European money centers
- The UAE supports the crypto industry via the Dubai Multi Commodities Centre and the Dubai International Financial Centre
The UAE has cultivated a robust ecosystem for crypto and blockchain innovation with more than 500 crypto startups are now based in Dubai’s free zones. One poster child for Dubai’s flexibility is Telegram’s choice of the city as the location for its “headquarters.” (Keep in mind that Telegram is a distributed and decentralized organization, so the “staff” in Dubai is modest in size for the company’s size.) Plus, the UAE has implemented measures to ensure investor protection and market stability with Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements. Also, the Central Bank of the UAE approved a custodial insurance product to protect financial institutions and their clients from potential losses due to hacks or internal fraud.
One key question: Are there technical professionals with crypto experience in Dubai? The answer, in part, can be approached via the attendance at the November 2024 TON Foundation Gateway Conference. The conference attracted about 400 people in 2023. In November 2024, more than 2000 crypto savvy professionals participated in two day program held in Dubai. The UAE may be on the path to becoming the hot spot for crypto innovation.
Stephen E Arnold, January 7, 2025
Love Phishing? New Angling Gear to Try
January 6, 2025
Registrars have long run out of TLDs (top-level domains) aka the endings at the end of websites. TLDs like .com, .net, .org, etc. are hot commodities, but in order to expand their offerings registrars added new endings that are unfortunately a new tool for bad actors says Krebs On Security: “Why Phishers Love New TLDs Like .shop, .top and .xyz“. Phishing attacks increased 40% in 2024, mostly on Web sites that end with .shop, .top., xyz, and other generic TLDs (gTLDs).
Interisle Consulting conducted a study on new gTLDs sponsored y many anti-spam organizations. Interisle discovered that gTLDs accounted for only 11% of the new domain market, but 37% of all cybercrime domains from September 2023 to August 2024.
The golds domains are very inexpensive to purchase. They can then be used on Web sites used for phishing scams and more:
“Spammers and scammers gravitate toward domains in the new gTLDs because these registrars tend to offer cheap or free registration with little to no account or identity verification requirements. For example, among the gTLDs with the highest cybercrime domain scores in this year’s study, nine offered registration fees for less than $1, and nearly two dozen offered fees of less than $2.00. By comparison, the cheapest price identified for a .com domain was $5.91.”
Scammers are very excited because the Internet Corporation for Assigned Names and Numbers (ICANN) is about to drop a boatload of new gTLDs sometime in 2026. Despite all the information about bad actors using the gTlDs, ICANN will press forward. Interisle also found that phishers can avoid paying for gTlDs with subdomain providers like weekly.com, pages.dev, and blogspot.com.
Registrars don’t care as along as they get paid. They don’t ask any questions, slap on anonymity; and collect referral fees until someone shuts the bad actors down.
Whitney Grace, January 6, 2025
Russian Drug Trade Likes That Cryptocurrency
January 3, 2025
No smart software involved. Just a dinobaby’s work.
High tech innovation meets traditional thuggery in Russia’s expanding drug trade. The Global Initiative Against Transnational Organized Crime summarizes its recent report in, “Breaking Klad: Russia’s Dead Drop Drug Revolution.” The write-up includes links to download the report and a related press release. First up, the innovation:
“There has been a groundbreaking shift in the global drug trade, pioneered in Russia and now spreading globally. Unlike traditional drug trafficking models, this system leverages darknet markets and cryptocurrency for anonymous transactions, allowing buyers to retrieve drugs from hidden physical locations, or ‘dead drops,’ rather than direct exchanges. Driven by large platforms such as Kraken, Mega, and Blacksprut [sic], Russian darknet markets control 93% of the global share, generating approximately $1.5 billion in revenue in 2023 alone. This dominance marks a new era for organized crime, with Russia’s digital drug economy vastly surpassing traditional Western darknet markets in scope and influence.”
We are told this digital shift was prompted by several factors. Increasingly restrictive anti-drug policies and strained trade relations with the West contribute. Also, drug dealers now have the technology to give their clients (and themselves) the convenience and anonymity they desire. Wonderful. The writeup mentions that, within Russia, trade in cheap-to-make synthetic drugs like mephedrone is overtaking traditional imports like cocaine and heroin. Which leads us to the thuggery:
“Youth are drawn into this high-tech drug economy, often working as couriers or ‘kladmen’ for online shops—a job that comes with high risks, including violence, criminal charges, and addiction. Violence has become endemic in the system, with enforcers, known as ‘sportsmen,’ meting out harsh punishments for couriers suspected of theft or negligence. This pervasive violence, combined with the easy availability of highly addictive synthetic drugs, is fueling a public health crisis and contributing to rising incarceration rates among young Russians.”
These young people may find miserable company in a growing number of countries; the report warns this model is spreading beyond Russia’s borders. Authorities must adapt to the new reality. Understanding Russia’s darknet markets will help, advises the report.
Cynthia Murrell, January 3 , 2025
FOGINT: What Do the Most Recent Telegram Function Enhancements Portend for 2025?
January 2, 2025
This is a report from the FOGINT research team.
For a company without a permanent office with staff who show up everyday, Telegram has been busy in December 2024. One good example is Telegram’s chopping up the video stream from its Gateway Conference held in early November 2024. The individual talks with their unique Telegram / TON Foundation quirkiness are available on YouTube at this link. One can mostly parse some speakers’ content using the Google caption function.
Also, a “real” news service has collected several other Telegram and its ecosystem announcement in “Telegram Rolls Out Third-Party Account Verification, Filters.” For those unfamiliar with Telegram, the service offered a verification process. That service remains, and “has now launched a new project to let already-verified third-party authorities, such as food quality regulators or educational consortiums, verify an account.” The article also points out that Telegram has added “filters” to the baked in search and retrieval service. FOGINT wants to point out that the search service is not very good. Retrieval remains spotty. The only way to find certain content is to monitor specific public and private groups. The content from these groups can then be downloaded or sucked from the service with a well-crafted script tuned to observe Telegram’s quite specific blocks on bulk downloading. According to the cited article, Telegram has added:
- Emoji reactions
- Sending gifts (this is a money generating angle)
- Search filters for private chats, group chats, and channels.
The write up does not ask the question, “What is the direction these features suggest Telegram and its associated entities are heading in 2025?”
Here’s FOGINT’s take on the path Telegram is likely to follow:
- Freeing Pavel will be a top priority
- Amping up Telegram and the TON Foundation’s crypto activities. (Telegram is the platform for TON Foundation; the Foundation is the marketing and developer magnet for the TONcoin.)
- Provide functions and services like third party verification to show the French judiciary and others that Telegram does have “real” users and can provide investigators with some useful information maybe.
But the big priority after the “Free Pavel” action is crypto; specifically, making the Telegram platform the hub for crypto gaming and possibly some allied services like automating the movement of crypto from one coin and wallet to other wallets and coins. Tie ups with the Ku Group and other organizations providing crypto alternatives to traditional and regulated financial systems are on board and rolling out integrated services at this time.
Stephen E Arnold, January 2, 2025
FReE tHoSe smaRT SoFtWarEs!
December 25, 2024
No smart software involved. Just a dinobaby’s work.
Do you have the list of stop words you use in your NLP prompts? (If not, click here.) You are not happy when words on the list like “b*mb,” “terr*r funding,” and others do not return exactly what you are seeking? If you say, “Yes”, you will want to read “BEST-OF-N JAILBREAKING” by a Frisbee team complement of wizards; namely, John Hughes, Sara Price, Aengus Lynch, Rylan Schaeffer, Fazl Barez, Sanmi Koyejo, Henry Sleight, Erik Jones, Ethan Perez, and Mrinank Sharma. The people doing the heavy lifting were John Hughes (a consultant who does work for Speechmatics and Anthropic) and Mrinank Sharma (an Anthropic engineer involved in — wait for it — adversarial robustness).
The main point is that Anthropic linked wizards have figured out how to knock down the guard rails for smart software. And those stop words? Just whip up a snappy prompt, mix up the capital and lower case letters, and keep sending the query to a smart software. At some point, those capitalization and other fixes will cause the LLM to go your way. Want to whip up a surprise in your bathtub? LLMs will definitely help you out.
The paper has nifty charts and lots of academic hoo-hah. The key insight is what the many, many authors call “attack composition.” You will be able to get the how-to by reading the 73 page paper, probably a result of each author writing 10 pages in the hopes of landing an even more high paying, in demand gig.
Several observations:
- The idea that guard rails work is now called into question
- The disclosure of the method means that smart software will do whatever a clever bad actor wants
- The rush to AI is about market lock up, not the social benefit of the technology.
The new year will be interesting. The paper’s information is quite the holiday gift.
Stephen E Arnold, December 25, 2024
FOGINT: Telegram Gets Some Lipstick to Put on a Very Dangerous Pig
December 23, 2024
Information from the FOGINT research team.
We noted the New York Times article “Under Pressure, Telegram Turns a Profit for the First Time.” The write up reported on December 23, 2024:
Now Telegram is out to show it has found its financial footing so it can move past its legal and regulatory woes, stay independent and eventually hold an initial public offering. It has expanded its content moderation efforts, with more than 750 contractors who police content. It has introduced advertising, subscriptions and video services. And it has used cryptocurrency to pay down its debt and shore up its finances. The result: Telegram is set to be profitable this year for the first time, according to a person with knowledge of the finances who declined to be identified discussing internal figures. Revenue is on track to surpass $1 billion, up from nearly $350 million last year, the person said. Telegram also has about $500 million in cash reserves, not including crypto assets.
The FOGINT’s team viewpoint is different.
- Telegram took profit on its crypto holdings and pumped that money into its financials. Like magic, Telegram will be profitable.
- The arrest of Mr. Durov has forced the company’s hand, and it is moving forward at warp speed to become the hub for a specific category of crypto transactions.
- The French have thrown a monkey wrench into Telegram’s and its associated organizations’ plans for 2025. The manic push to train developers to create click-to-earn games, use the Telegram smart contracts, and ink deals with some very interesting partners illustrates that 2025 may be a turning point in the organizations’ business practices.
The French are moving at the speed of a finely tuned bureaucracy, and it is unlikely that Mr. Durov will shake free of the pressure to deliver names, mobile numbers, and messages of individuals and groups of interest to French authorities.
The New York Times write up references profitability. There are more gears engaging than putting lipstick on a financial report. A cornered Pavel Durov can be a dangerous 40 year old with money, links to interesting countries, and a desire to create an alternative to the traditional and regulated financial system.
Stephen E Arnold, December 23, 2024
FOGINT: Big Takedown Coincident with Durov Detainment. Coincidence?
December 19, 2024
This blog post is the work of an authentic dinobaby. No smart software was used.
In recent years, global authorities have taken down several encrypted communication channels. Exclu and Ghost, for example. Will a more fragmented approach keep the authorities away? Apparently not. A Europol press release announces, “International Operation Takes Down Another Encrypted Messaging Service Used by Criminals.” The write-up notes:
“Criminals, in response to the disruptions of their messaging services, have been turning to a variety of less-established or custom-built communication tools that offer varying degrees of security and anonymity. While the new fragmented landscape poses challenges for law enforcement, the takedown of established communication channels shows that authorities are on top of the latest technologies that criminals use.”
Case in point: After a three-year investigation, a multi-national law enforcement team just took down MATRIX. The service, “by criminals for criminals,” was discovered in 2021 on a convicted murderer’s phone. It was a sophisticated tool bad actors must be sad to lose. We learn:
“It was soon clear that the infrastructure of this platform was technically more complex than previous platforms such as Sky ECC and EncroChat. The founders were convinced that the service was superior and more secure than previous applications used by criminals. Users were only able to join the service if they received an invitation. The infrastructure to run MATRIX consisted of more than 40 servers in several countries with important servers found in France and Germany. Cooperation between the Dutch and French authorities started through a JIT set up at Eurojust. By using innovative technology, the authorities were able to intercept the messaging service and monitor the activity on the service for three months. More than 2.3 million messages in 33 languages were intercepted and deciphered during the investigation. The messages that were intercepted are linked to serious crimes such as international drug trafficking, arms trafficking, and money laundering. Actions to take down the service and pursue serious criminals happened on 3 December in four countries.”
Those four countries are France, Spain, Lithuania, and Germany, with an assist by the Netherlands. Interpol highlights the importance of international cooperation in fighting organized crime. Is this the key to pulling ahead in the encryption arms race?
Cynthia Murrell, December 19, 2024