Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TeleGrab did not crack Telegram’s encryption. In 2018, Cisco Talos described malware that stole files from infected computers, including Telegram Desktop cache and key files in its second reported variant. Those local files could be used to restore a Telegram session on another desktop and access session data. The episode shows the difference between breaking encryption and taking data from a device where an account is already in use.

How TeleGrab accessed Telegram data

Cisco Talos first observed TeleGrab on April 4, 2018, and reported a second variant on April 10. The first version collected browser credentials and cookies, as well as text files found on the system. The second added Telegram Desktop cache and key files and Steam login information. Talos published its report on May 16, 2018. Cisco Talos’s report describes collection from infected computers, not interception of encrypted network traffic.

The practical risk was session misuse: local Telegram Desktop files could help restore a session on an attacker-controlled desktop installation and expose session data. This is an endpoint compromise. If malware can read files or access a running app on a device, encryption cannot prevent it from seeing data available there.

What TeleGrab did not prove about encryption

The TeleGrab findings do not show that attackers decrypted Telegram traffic or defeated its encryption algorithms. Encryption protects data in particular states and paths; it is not a shield against malware with access to the endpoint where messages are displayed or session material is stored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is also inaccurate to say every Telegram conversation is end-to-end encrypted by default. Telegram distinguishes between cloud chats and Secret Chats, which have different encryption and storage models.

Cloud chats and Secret Chats are different

Chat type Encryption, according to Telegram Storage, according to Telegram
Cloud chats Server-client encryption Content is stored on Telegram’s servers in encrypted form
Secret Chats Client-client encryption Not stored on Telegram’s servers; available only on the devices where they originated

These distinctions are Telegram’s own descriptions in its FAQ and Privacy Policy. A Secret Chat’s device-bound design changes where its messages are available, but it does not make a compromised device trustworthy.

How to protect a Telegram account if a computer may be infected

Telegram’s current general account guidance includes using Secret Chats for sensitive conversations, enabling two-step verification, and setting a strong app passcode. These settings can strengthen account or app protections, but they are not guarantees against malware that controls a device. Telegram also cautions that root access can bypass operating-system protections and expose process memory or restricted storage.

  1. Stop using the suspected computer for sensitive account activity. Treat files and sessions on a potentially compromised device as exposed; changing chat type does not remove malware from it.
  2. Use a device you trust to review Telegram’s account protections. In Telegram, open Settings and locate Privacy and Security. Enable Two-Step Verification and set an app passcode; labels may vary by client or version.
  3. Use Secret Chats when you need Telegram’s device-specific client-client encryption. Start the Secret Chat with the intended contact from a supported Telegram app. Secret Chats are not the same as regular cloud chats.
  4. Address the computer compromise separately. Remove the malicious software or have the system repaired before signing in again. Account settings do not clean an infected computer.

For its broader warning about device compromise, Telegram says: “A user with root access can easily bypass security features built into the operating system, read process memory or access restricted areas, such as the internal storage.” That is general device-security guidance, not a TeleGrab-specific finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about TeleGrab today

The documented observations and variants date to 2018. The sources cited here do not establish that TeleGrab remains active or prevalent in 2026, and they provide no verified victim count or measured impact figure. Cisco Talos said its research identified the malware’s author with high confidence, but that statement does not name the author.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.