Recently, Telegram experienced a brief removal from Apple's App Store, only to be swiftly reinstated, with further details coming to light. Telegram's founder, Pavel Durov, revealed that the removal was the result of a "ransomware-style malicious attack." In this scheme, attackers intentionally embedded AI-altered child sexual abuse material within Telegram and reported it directly to Apple, in an attempt to coerce the app's removal.
Durov explained that the attackers employed automated accounts to insert illegal content into public groups. They also manipulated historical messages to evade moderation efforts. Consequently, Apple removed the app without first reaching out to Telegram for clarification. After Telegram promptly deleted the problematic content and banned the users involved, the app was restored to the App Store.
Durov cautioned that this attack method could present a systemic risk to all mobile apps that permit user-generated content. Furthermore, it highlights vulnerabilities in app store review mechanisms that can be easily exploited.
