Desktop
Step-by-step workflow guide for investigators
Threat Actor Telegram Investigation
Starting from a single alias associated with a threat actor group, this guide walks you through recovering the group's historical posting activity on Telegram, extracting the infrastructure they reference, tracing where those references surface across the dark web, and identifying the accounts behind them in Graph (Desktop). By the end, you will have a defensible list of accounts operating the group’s infrastructure.
Who is this for?
Threat intelligence analysts, law enforcement investigators, and intelligence teams tracking organised online groups — hacktivist collectives, fraud networks, or coordinated influence operations.
What is on this page?
A video walkthrough of a real organizational risk assessment case, followed by step-by-step guide in Maltego Graph (Desktop).
The workflow covers recovering associated channels and historical posts, isolating referenced URLs onto a clean graph, converting them into searchable phrases, searching dark web sources for where those references appear, identifying which networks the mentions came from, and resolving the accounts behind the infrastructure. A closing section covers what to do with that account list once you have it.
The workflow covers recovering associated channels and historical posts, isolating referenced URLs onto a clean graph, converting them into searchable phrases, searching dark web sources for where those references appear, identifying which networks the mentions came from, and resolving the accounts behind the infrastructure. A closing section covers what to do with that account list once you have it.
How to use this page?
Watch the video at the top for an end-to-end overview, then follow the written steps below to conduct an investigation using your own domain.
New to Graph?
No problem. Every platform feature mentioned in this guide links to the relevant product documentation so you can read up as you go.
A note on results
The steps here reflect what works for most customers in this use case. Because Graph (Browser) works with live data, results depend on what is actually available at the time you run Transforms. Maltego cannot guarantee the same outcome for every case.
Data providers used on this page
This workflow combines platform and dark web data included in the Person of Interest and Darkweb Data Pass modules:
— Telegram DB — historical profile and channel data for Telegram. Given an alias, it returns the profiles and groups associated with it, including historical records where the account has since changed.
— Telegram DB — historical profile and channel data for Telegram. Given an alias, it returns the profiles and groups associated with it, including historical records where the account has since changed.
— WebIQ — historical post content from Telegram channels. Returns the group's posting history going back a year or more, including posts, images, activity records, and the URLs referenced within them.
— Crowlingo — resolves messaging accounts associated with a given URL, letting you move from infrastructure back to the users promoting it.
— DarkOwl — a broad dark web index covering onion sites and other underground sources.
— DarkOwl — a broad dark web index covering onion sites and other underground sources.
Before you start:
Identify the starting point
Alias or channel name of the group you are investigating.
Access
- Download and install Graph (Desktop).
- Install the Darkweb and Person of Interest Data Pass modules from the Data Hub within Graph (Desktop).
Note: Basic users have limited access to the data providers used in this workflow more generally — some transforms may be unavailable or return restricted results depending on your plan tier.
Resources
This guide assumes basic familiarity with Graph (Desktop). Feature names link to the documentation where needed. It helps to have the following pages open before you start:
Video Overview
Watch a threat actor tracking workflow demonstration. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.
To enlarge, double-click on the video.
Step-by-Step Guide
Step 1: Find associated channels and retrieve posting history
Begin with the alias and find what channels it is connected to on Telegram.
How to:
How to:
- Add the Alias Entity to the graph.
- Open the Transform menu by right-clicking on the Entity.
- Navigate to Person of Interest → [POI] Get Historical Profile by Username (Telegram) [TelegramDB] to find the Telegram profile, groups, or channels associated with this alias.
- Get the posts of the group from the TelegramProfile Entity by running Get Historical Posts in (Telegram) [WEBIQ].
Alternative Transforms that you can run to find a Telegram profile are:
- Get Profile (Telegram) [Crowlingo]
- Search Groups and Channels (Telegram) [Crowlingo]
- Search Groups and Channels - Exact (Telegram) [Crowlingo]
What you can find
Once the Transform completes running, the graph will populate with the following:
- The groups linked to the alias, including historical profile records. Because this data is historical rather than live, it can surface associations that no longer appear on the current account.
- The channel's posting history, typically spanning a year or more.
- Alongside the post text you will get images that have been posted, records of channel activity, and the URLs referenced across all of those posts.
Step 2: Find more associated channels from the URLs
The URLs a group circulates are the strongest available indicator of where their activity is directed. Separating them from the noise of the full post history is what makes the next stages possible.
- Move all the URL Entities to a separate graph to keep the graphs organized by clicking Select by Type and choosing the URLs.
- Telegram URLs typically include the alias after "/" in "t.me/". For example t.me/scaryred24 means "scaryred24" is a link to the chat with the user or a link to the channel of the same name. We can use this to find more accounts that are connected to the original username.
- Add Alias Entities to the graph and rename them with the text after the "/" in the name of the URL Entities.
- Repeat Step 1 on the Alias Entities.
Tip:
It can be helpful to connect the URL to the specific post in the channel, where it appeared, for more context. To do that:
It can be helpful to connect the URL to the specific post in the channel, where it appeared, for more context. To do that:
- change the Entity type of the URL Entities into Phrase Entities.
- Run [Darkweb] Search posts (exact) [DarkOwl] Transform on the Phrase Entities.
- Graph will return Post Entities that you can explore further by double-clicking and navigating to the Entity Properties.
What's next?
-
Map the online presence of an alias identity, you're done after this workflow.
-
Set up a Threat Actor monitor for tracking the person's social media feed for threatening posts.
-
Check out the guide for Maltego Evidence for collecting and preserving social media posts from the person's of interest account before it disappears,
Other guides you might find useful:
Give us your Feedback!
Copyright © 2026
What is Maltego?
Write your awesome label here.
