USENIX Security2025Top-tier venue
Characterizing and Detecting Propaganda-Spreading Accounts on Telegram
Klim Kireev, Yevhen Mykhno, Carmela Troncoso, Rebekah Overdorf
Abstract
Information-based attacks on social media, such as disinformation campaigns and propaganda, are emerging cybersecurity threats. The security community has focused on countering these threats on social media platforms like X and Reddit. However, they also appear in instant-messaging social media platforms such as WhatsApp, Telegram, and Signal. In these platforms information-based attacks primarily happen in groups and channels, requiring manual moderation efforts by channel administrators. We collect, label, and analyze a large dataset of more than 17 million Telegram comments and messages. Our analysis uncovers two independent, coordinated networks that spread pro-Russian and pro-Ukrainian propaganda, garnering replies from real users. We propose a novel mechanism for detecting propaganda that capitalizes on the relationship between legitimate user messages and propaganda replies and is tailored to the information that Telegram makes available to moderators. Our method is faster, cheaper, and has a detection rate (97.6%) 11.6 percentage points higher than human moderators after seeing only one message from an account. It remains effective despite evolving propaganda.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bc1a2f94-0e43-4165-8a8f-a2b1de629879Cited by top-tier papers3
- Stayin' Alive: How Global Stolen Data Markets Thrive on TelegramTina Marjanov, Taro Tsuchiya, Konstantinos Ioannidis, Jack Hughes et al.USENIX Security 2026 · 2 citations
- Customization under Fire: Plugin Poisoning in Text-to-Image EcosystemJiahao Chen, Xing He, Yong Yang, Xinfeng Li et al.CCS 2026 · 2 citations
- Cross-National Information Attacks: A Two-Decade Analysis of Troll Behavior in KoreaJaehong Kim, Hyeonseung Kim, Jiseon Kim, Alice Oh et al.USENIX Security 2026
Builds on4
- Scalable and Generalizable Social Bot Detection through Data SelectionKai-Cheng Yang, Onur Varol, Pik-Mai Hui, Filippo MenczerAAAI 2020 · 385 citations
- The Psychological Well-Being of Content Moderators: The Emotional Labor of Commercial Moderation and Avenues for Improving SupportMiriah Steiger, Timir J. Bharucha, Sukrit Venkatagiri, Martin J. Riedl et al.CHI 2021 · 168 citations
- TrollMagnifier: Detecting State-Sponsored Troll Accounts on RedditMohammad Hammas Saeed, Shiza Ali, Jeremy Blackburn, Emiliano De Cristofaro et al.S&P 2022 · 40 citations
- Specious Sites: Tracking the Spread and Sway of Spurious News Stories at ScaleHans W. A. Hanley, Deepak Kumar, Zakir DurumericS&P 2024 · 18 citations
Related papers
- Exposing Cross-Platform Coordinated Inauthentic Activity in the Run-Up to the 2024 U.S. ElectionFederico Cinus, Marco Minici, Luca Luceri, Emilio FerraraWWW 2025 · 22 citations
- Networks and Influencers in Online Propaganda Events: A Comparative Study of Three Cases in IndiaAnirban Sen, Soham De, Joyojeet PalCSCW 2024 · 2 citations
- The Conspiracy Money Machine: Uncovering Telegram's Conspiracy Channels and their Profit ModelVincenzo Imperati, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini et al.USENIX Security 2025
- Detecting Propaganda Techniques in MemesDimitar Dimitrov, Bishr Bin Ali, Shaden Shaar, Firoj Alam et al.ACL 2021
- Analyzing the Strategy of Propaganda using Inverse Reinforcement Learning: Evidence from the 2022 Russian Invasion of UkraineDominique Geissler, Stefan FeuerriegelCSCW 2024 · 4 citations
