Telegram deepfake bots are built to survive takedowns, and target women by default

CIR

13 min read

CIR

CIR 's photo

Share Article

By Tom Jarvis

Warning: This article discusses image-based sexual abuse, including abuse involving children and includes graphic source screenshots from CIR’s investigation. Readers may find the content distressing 

 

Telegram deepfake bots are only the visible face of a wider abuse business. CIR’s analysis found referral networks, backup websites, payment routes and upstream generation providers that can keep the ecosystem alive after one bot disappears. 

In late 2025, a UK secondary school was targeted by an extortion attempt involving AI-generated abuse images of pupils. The Guardian reported that the Internet Watch Foundation (IWF) classified 150 images as child sexual abuse material (CSAM) and stored their unique file fingerprints, allowing detection if they appeared online without the need for law enforcement to possess the files themselves. The IWF did not believe the case was isolated. By November 2025, UK reports of AI-generated CSAM had more than doubled, from 199 to 426, with girls making up 97% of victims. 

That case shows why Telegram deepfake bots matter beyond the app where they appear. The bots reviewed by CIR are not just offensive search results or disposable accounts. They are storefronts for a commercially organised abuse system that can survive individual takedowns because the audience, money, backup routes and generation capacity often sit elsewhere.  

The scale already points to a wider market. WIRED identified at least 50 Telegram bots in 2024 that claimed to create explicit images or videos and collectively displayed more than 4 million monthly users. In January 2026, the Guardian reported on large Telegram channel networks used to create and share AI-generated nude images. CIR’s earlier Grok analysis showed how abuse scales when image-generation access is easy; Telegram shows how it scales when discovery, payment and relaunch paths are also easy. The question is therefore not only whether a model refuses a prompt, but whether the surrounding product pathway makes non-consensual sexual image creation easy to find, repeat, monetise and share. 

Understanding, or even eradicating, the Telegram layer will not stop the most egregious cases, but it highlights the resilience of the infrastructure and the multiple ways these organisations can generate funds and provide their illicit services to users. It also highlights a “gateway” effect where users are enticed in with free credits, turning curiosity into an ability to generate images at scale. 

CIR’s analysis reviewed public Telegram bot interfaces, public channels and posts, referral messages, linked web pages, payment prompts, public gallery features, bot metadata and screenshots. The timeframe included two weeks of research in June 2026, looking back through posts historically. This captured references and links from the past which have survived takedowns. As a result, many links were already dead, and the live bots viewed were just a snapshot of what has been available over the past years. It did not require uploading images of non-consenting people, generating abusive outputs, or identifying victims. The findings should be read as a map of recurring behaviours, not as a claim that every bot uses the same infrastructure. 

 

Figure 1: A Telegram nudification bot reviewed by CIR displayed almost 60,000 monthly users 

Greeted by a menu

The user-facing product is deliberately simple. A person opening one of these bots is usually shown a menu, a credit balance and an upload prompt. A “nudifier” is a service that claims it can alter a source image to create nude or sexualised outputs. In many cases, it simply “erases” the clothes and depicts nudity in an image. Other examples involve video transformations, which can include the subject removing their clothes or performing sex acts. In Telegram, that abuse can be presented as a normal app journey: choose a mode, upload an image, spend credits and receive a result. 

The design is important to consider because it strips away friction and context. The concept of “nudification” has been around for a long time, with tools like Photoshop offering the ability to create fake images; however, the ease of producing content en masse – with few technical skills required – is what lowers the barrier to abuse. What once required time and dedication is now a drag-and-drop workflow, meaning the intent-to-action process is minimal. 

The bot does not meaningfully establish whether the person in the image consented. It does not reliably stop someone uploading a photo of a classmate, colleague, former partner, influencer or stranger. It presents another person’s likeness as raw material for a paid or rewarded output. 

The gendered assumptions are clear from the outset. In all products reviewed by CIR, the advertised models depicted female anatomy and appeared designed for images of women as inputs. Some options allowed images of men, but often still placed a woman as the sexualised subject. The same pattern has already surfaced in offline harm. In Almendralejo, Spain in 2023, more than 20 schoolgirls received AI-generated sexual images made from their social media photos and shared through WhatsApp, according to Euronews. Several needed psychological support and some faced blackmail, leveraged by the fake images. The Guardian later reported that a youth court in Badajoz convicted 15 minors over child-abuse imagery and moral-integrity offences, with probation and education measures imposed. 

However, not every Telegram bot case involves children. The product model is built around turning everyday photos into sexualised material without consent checks. When that design is combined with free credits, daily rewards and public sharing, it creates a low-cost route from curiosity to repeated abuse. 

Free credits make the first act easier. Several bots reviewed by CIR gave new users enough balance to test a feature, then used daily bonuses, lotteries, referral rewards or premium modes to encourage return visits. Less explicit or more generic features were sometimes available without payment, while more sexualised options were visibly promoted at a higher price. The product funnel turns abuse into a habit-forming service. 

Figure 2: A bot menu packages abuse as product tiers with thumbnails, prices and mode names 

The harm does not stop at the image

Several bots and linked services reviewed by CIR exposed user-generated outputs through public or semi-public galleries, rankings, feeds or share prompts. A private act of abuse can therefore become a distribution system. 

Public galleries create a second layer of victimisation. A person whose photo was uploaded without consent may then be shown to other users, copied, ranked, forwarded or used as proof that the bot works. Where bots reward users for popular posts, the product gives users an incentive to publish the output rather than keep it private. 

Source images visible in some reviewed examples appeared to come from ordinary social media contexts, including screenshots resembling Instagram or similar platforms. That is a central enforcement problem. A person does not need to have shared intimate imagery to be targeted. A normal profile photo, school image or public post can become the input. 

South Korea’s 2024 Telegram deepfake crisis showed how quickly this harm can spread across real communities. NBC News reported a national outcry over sexual deepfakes shared through Telegram. The Conversation described abuse affecting more than 500 schools and universities, with mainly female students and teachers targeted in Telegram groups and bot-driven “humiliation rooms”. Many victims were minors, and most of those arrested were teenagers. 

The South Korea case also showed that social design can amplify harm. Reporting described referral rewards and gamified participation that encouraged users to bring others into abuse spaces. Telegram cooperated only after public pressure, according to reporting at the time. 

For investigators and platforms, gallery functions should therefore be treated as high-risk distribution surfaces. A bot that lets users publish generated outputs, vote on them, rank them or earn credits from them is not only a private generation tool. It is helping circulate image-based sexual abuse. 

Privacy claims by operators should be treated sceptically. Some bots promise that uploads are private or deleted, while others say little about storage, retention, human review, logging, model training or backend processors. Users cannot verify where images are sent, whether outputs are cached, who can access them or whether an upstream service receives the original photograph. 

Figure 3: A public gallery view showed user-generated outputs visible inside a linked service 

Built to be found

Many Telegram deepfake bots are not hidden in obscure corners of the internet. CIR found bots promoted through public posts, external websites, referral campaigns and searchable Telegram surfaces. The user journey can be short: find a bot, open it, receive free credits, upload an image and begin generating content with little technical knowledge. 

Referral systems are central to that growth. Many bots give users a personal referral link and reward them with credits, daily points or premium access when others join. Some combine this with retention mechanics such as daily bonuses, lotteries or “lucky” draws. The result resembles affiliate marketing and mobile-game design: users are rewarded not only for using the bot, but for repeatedly promoting it. 

CIR reviewed public posts where users stacked links to multiple image-manipulation and video-generation bots in one place. The identifiers, bot names and active links are not published here because they would help readers find the services. The analytical point is that referrals form an acquisition layer. They help operators rebuild audiences when a bot disappears. 

Referral posts also reveal how the ecosystem extends beyond Telegram. Some links route through external pages before sending users back into the app. Those pages can support click tracking, referral attribution, analytics, bot rotation or backup routing. Their presence shows that the abuse system is not contained in one platform interface, even when Telegram is the most visible doorway.  

That layer should be an enforcement target in its own right. Platforms can remove or downrank public posts that aggregate referral links, act on repeated promotional phrases and suspend accounts that repeatedly advertise non-consensual image-generation tools. Search-reporting systems should accept bot aliases, recurring phrases and backup-domain names, not only the active handle of the current bot. Otherwise, the public reporting process rewards the operator’s cheapest tactic: rotate the visible endpoint while leaving the promotion network undisturbed.  

Figure 4: A bot welcome screen offering free credits, referral rewards, daily bonuses and a lucky spin 

When the bot dies, the website lives

Individual bot takedowns can reduce immediate access, but they do not necessarily break the system. CIR observed bots directing users to permanent web links, pinned messages and backup routes designed to outlast a Telegram handle. Some websites appeared to point users towards replacement bots when the previous bot was unavailable. 

This makes the web layer more than a convenience feature. It preserves continuity. A bot can be removed, renamed or blocked while the website, referral structure, external channel or redirect path remains in place. Users who have been trained to look for a backup route can move to the next endpoint.  

Many bots had serial numbers in their names, like @_bot34, @_bot35, and @_bot36. These give indication to the number of “burner” bots that have been taken down, only for new bots to take their place. It highlights that mere Telegram disruption is insufficient for tackling the issue. 

CIR also observed that many of these websites were blocked in the UK while their Telegram bots remained available. UK users were still able to access the websites through virtual private networks (VPNs) in all tested cases. A VPN is a service that can route a user’s connection through another location, sometimes allowing access to sites blocked in the user’s country. 

This is why domain blocking and bot removal should be joined up. An evidence packet should connect the bot, backup domain, referral posts, public channels and payment prompts. If each layer is reported separately, the operator can lose one endpoint while keeping the acquisition and retention machinery intact. For enforcement teams, the most useful evidence is often not the latest bot handle but the repeated infrastructure that makes the next handle easy to launch. 

Figure 5: A bot message directs users to a permanent website and other recovery routes 

Burner and affiliate storefronts

The technical stack behind Telegram deepfake bots is typically modular. Telegram often functions only as the visible storefront, providing the bot interface, upload prompts, menus, referral links and delivery channel, while the controlling code, payment systems and image or video generation infrastructure operate elsewhere through hosted workflows, web services or third-party APIs. This separation makes the visible bot relatively disposable: even if a Telegram account is removed, the operator may retain the backend code, credit balances, referral network, payment route, backup website and upstream generation provider. Some operators may therefore function primarily as resellers, collecting payment through Telegram and forwarding generation requests to a larger service rather than maintaining their own models. WIRED reported in January 2026 that some larger deepfake websites have offered APIs to others, creating non-consensual image and video generators. CIR treats this as a plausible commercial pattern, not proof for every bot. 

This architecture may explain why apparently separate bots share menus, pricing tiers, error messages, watermarks, gallery layouts or newly introduced features, all of which may indicate a common upstream supplier and should be recorded as investigative leads. Public model marketplaces, reusable checkpoints,  bot frameworks and hosted computer-vision workflows further reduce the expertise and infrastructure required to create such services.  

A public code example reviewed by CIR demonstrated that a minimally safeguarded, self-hosted Telegram nudification bot could be built from publicly available components with little technical difficulty. To avoid facilitating replication, CIR does not publish the repository, model endpoint, active service names, dependency recipe or operational instructions. 

Figure 6: Telegram deepfake bot architecture types, showing storefront, backend, payment, referral, backup-domain and upstream API layers 

Following the money

Payment turns these bots from isolated abuse tools into a service economy. Users normally see credits, bundles, discounts and premium modes rather than a clear price per output. This abstraction makes spending feel smaller, lets operators vary prices by feature and turns free credits into a gateway to paid use. 

Telegram Stars are especially significant because they are built into Telegram bot and mini-app flows. Stars are Telegram’s in-app currency for digital goods and services. Telegram says digital goods sold through bots must use Stars and that the invoice interface for digital goods does not require buyers to enter personal information such as a full name, shipping address or card details. 

Some bots also advertise cryptocurrency or external payment pages. Those routes may give operators more control over pricing, subscriptions, refunds, cross-platform access or perceived anonymity. They also create evidence. Wallet addresses, QR codes, invoice text, payment windows, support accounts and repeated checkout wording can connect services that otherwise appear separate. Public reporting should describe those artefacts without publishing the identifiers. 

The payment layer is also a control system. Credits can be tied to referrals, daily check-ins, faster queues, higher-resolution outputs or “private” generation. If a bot is reselling an upstream API, credits also allow the operator to manage the margin between what the user pays and what the upstream service charges. 

This is why payment evidence can be more durable than a brand name. A bot can change its handle, menu wording or public channel, but repeated credit bundles, invoice text, refund language, support accounts or checkout flows can connect services that appear separate.  

Bellingcat has documented non-consensual deepfake services attempting to disguise or route payments through mainstream services and adjacent marketplaces. For Telegram bots, the same logic applies. Payment providers, wallet services and platform payment systems should focus on recurring commercial signals, not just the latest bot name. 

Investigators do not need to complete a purchase to document most payment infrastructure. Screenshots of public menus, credit bundles, invoice previews, crypto prompts, support instructions and refund policies can show monetisation and preserve leads for platform, payment-provider or law-enforcement reporting. 

Figure 7: A payment prompt shows how credits can be bought through Telegram Stars or other routes 

Why bot-by-bot takedown fails

Bot-by-bot takedowns are necessary, but they are a weak endpoint strategy on their own. The visible Telegram bot is often the easiest asset for an operator to replace. The harder assets to rebuild are the audience, referral network, backup domain, payment route, public gallery, upstream API relationship, hosting account and repeated promotional language that make the next bot viable. 

CIR’s earlier analysis of abuse involving Grok identified five emerging lessons: block repetitive abuse phrases; prioritise prolific offenders; apply safeguards across every access point; respond quickly to new workarounds; and formally recognise AI-assisted sexual image manipulation as abuse. Those lessons apply to Telegram deepfake bots, but must be extended beyond individual prompts and users to the commercial and technical infrastructure surrounding them. 

Recommendations include: 

  • Detect repeated abuse signals across the whole service. CIR’s Grok analysis found that much of the abuse relied on near-identical phrases that could be identified and blocked without preventing legitimate image generation. In Telegram systems, those signals may appear not only in user prompts but also in bot names, commands, menu labels, referral posts, public gallery captions, search terms, payment instructions and messages directing users to backup services. 
  • Prioritise high-volume operators and commercial enablers. The Grok analysis showed the value of focusing enforcement on prolific users rather than treating every abusive request as an unrelated incident. For Telegram, this should include promoters, bot operators, referral-network administrators, gallery uploaders and payment recipients, as well as individual users. Accounts or services repeatedly directing traffic to multiple deepfake bots may be more important disruption targets than any single storefront. 
  • Apply safeguards across every access point. The Grok analysis warned that restrictions at one interface achieve little if the same capability remains accessible elsewhere. The equivalent Telegram ecosystem may include bots, mini-apps, public channels, backup websites, shortened links and upstream APIs. Safeguards and enforcement, therefore, need to cover the full route through which users discover, purchase and access the service. 
  • Treat workarounds and relaunches as connected incidents. The fourth Grok lesson was that platforms must identify and close new workarounds quickly. On Telegram, operators may respond to enforcement by changing handles, cloning bots, redirecting backup domains, altering keywords or moving users through referral channels. Repeated menu structures, promotional language, payment details, domains and referral identifiers can help platforms and investigators recognise a relaunch as part of an existing operation rather than as an entirely new case. 
  • Recognise explicit deepfake generation as a distinct form of abuse. CIR’s Grok analysis argued that formally recognising AI-assisted sexual image manipulation as abuse creates the basis for consistent enforcement and accountability. Telegram should similarly treat AI nudification and explicit deepfake bots as a distinct abuse category, rather than relying only on general pornography reports. Enforcement should cover bot names, search terms, menus, public galleries, referral spam and backup-link messages that advertise the creation of non-consensual intimate images. 
  • Use leverage across the wider provider ecosystem. Telegram is only one layer of the service. Domain registrars, hosting companies, DNS providers and URL shorteners may be able to act against backup and redirect infrastructure. Payment providers and wallet services can investigate repeated checkout signals. Upstream model or API providers can act where several storefronts appear to depend on the same generation service. Search providers, app stores and social platforms can also reduce discovery of external pages that advertise replacement bots or explain how to access them. 
  • Build regulation around the whole system, not only the final image. The UK has criminalised creating or requesting the creation of non-consensual intimate deepfakes of adults. Ofcom has also recommended that certain regulated services use hash-matching technology to detect intimate image abuse and reduce its spread. These measures will be most effective when regulators and providers consider how generation, payment, promotion, distribution and relaunch routes may be divided across several services. 

Investigate without creating additional harm. Evidence collection should prioritise public bot metadata, menus, referral posts, backup-domain redirects, payment prompts and policy claims. Investigators and journalists should not need to upload images of non-consenting people, generate abusive outputs, pay operators without a clear and lawful investigative need, or publish active identifiers that could direct new users towards the service.

 


 

Tom Jarvis is a Senior Investigations & AI Automation Specialist at CIR

Share Article