Telegram Deepfake Bots Are a Business, Not a Bug: Why Takedowns Alone Don't Work
A recent investigation by the Centre for Information Resilience (CIR) mapped something that most coverage of "deepfake bots" misses: these aren't disposable novelty accounts. They're commercially organized services — with referral programs, payment systems, backup infrastructure, and public galleries — built to survive individual takedowns. Understanding that structure changes what an effective response actually looks like.
A product, not an exploit
The scale of this problem is easy to understate. The Guardian reported on a UK secondary school targeted by an extortion attempt involving AI-generated abuse images of pupils, with the IWF classifying and fingerprinting 150 images from that case alone — and the IWF has said it doesn't believe that case was isolated.
The bots CIR reviewed present the way any consumer app does: a menu, a credit balance, an upload prompt. That framing matters. Nudification — using software to strip clothing from an image or fabricate explicit content — isn't new; crude versions have existed since Photoshop. What's changed is that producing this content at scale no longer takes any real skill or effort. The distance between having the impulse and generating the image has collapsed to a few taps.
None of the products CIR examined made any real attempt to establish consent. A photo of a classmate, a colleague, an influencer, or a stranger is treated as raw material. And the gendered pattern is consistent and deliberate: the models reviewed were built around female subjects, reflecting the same dynamic seen in Spain's 2023 Almendralejo case, where more than 20 schoolgirls had sexualized images generated from their social media photos as reported by Euronews, and in South Korea's 2024 crisis, where reporting from NBC News described "humiliation rooms" targeting mostly female students and teachers.
Free credits turn curiosity into a habit
Several bots CIR reviewed gave new users enough free credits to try the product, then used daily bonuses, referral rewards, and premium tiers to bring people back. It's the same mechanic mobile games use to drive retention, applied to a product whose output is abuse. The less explicit features are often free; the more sexualized options are priced higher and promoted more visibly. That's a funnel, not an accident.
The distribution layer compounds the harm. Some services expose generated images through public or semi-public galleries, rankings, or share prompts — turning a private act of abuse into something copied, ranked, and forwarded. A person doesn't need to have shared an intimate photo of themselves to become a target. An ordinary profile picture or school photo is enough to become the input.
Why removing one bot rarely works
CIR's analysis found that the visible bot is usually the easiest part of the operation to replace. The harder assets to rebuild — the audience, the referral network, the payment routing, the backup domains, the upstream generation capacity — often sit outside Telegram entirely, in web infrastructure designed specifically to survive a single account being banned. Take down the storefront, and the operator can relaunch the same customer base against a new one within hours.
A bot is disposable. The infrastructure behind it — audience, payment routing, backup domains, upstream generation access — is not. Enforcement aimed only at the visible endpoint leaves the part that actually matters untouched.
This is why CIR's recommendations focus on connected infrastructure rather than individual accounts: treating repeated menu structures, promotional language, and payment patterns as signals that link a "new" bot to a previous takedown, rather than investigating each one in isolation.
Where detection actually fits
Platform moderation and legal enforcement are necessary and they're not close to sufficient on their own — the asymmetry between how fast this content is created and how slowly it gets reported and removed is the structural problem. Detection has to sit earlier in that chain, not just at the reporting stage.
Image detection at upload
Flagging AI-manipulated or generated images before they circulate, rather than after a report has already been filed. See UncovAI's image detection.
Video and voice detection
The same commercial pattern extends to video transformations and cloned voices — both need dedicated detection, not just image checks. See video and audio detection.
Backup-link and phishing detection
The websites and redirect pages that keep an operation alive after a bot is banned are themselves detectable infrastructure. See URL detection.
Built for trust & safety teams
Platforms and investigators need detection that works at the volume this problem operates at, not one-off manual checks. See who UncovAI is built for.
What actually needs to change
CIR's recommendations, addressed to platforms, regulators, and the wider provider ecosystem, are worth restating because they apply well beyond Telegram:
Detect signals across the whole service, not just user prompts — recurring bot names, menu labels, referral posts, and payment instructions all carry the same fingerprint. Prioritize the operators and promoters moving the most volume, not just individual accounts. Close every access point at once — a restriction on one bot achieves nothing if a mini-app or backup site offers the same capability. Treat relaunches as continuations of the same operation, not new cases starting from zero. Recognize AI-generated sexual imagery as its own abuse category, distinct from general content moderation. And critically, extend accountability up the stack — to domain registrars, hosting providers, payment processors, and the upstream generation services some of these storefronts resell access to.
If you or someone you know is affected
These services exist specifically to help remove this content — you don't need to have technical skill or even keep the image to use them.
- Take It Down (NCMEC) ↗ For anyone under 18 (or who was under 18 when the image was taken). Creates a digital fingerprint so platforms can detect and remove the content — the image itself never leaves your device.
- StopNCII.org ↗ The equivalent service for adults over 18 affected by non-consensual intimate imagery.
- Internet Watch Foundation ↗ UK-based hotline for reporting child sexual abuse material anywhere in the world, with international takedown partnerships.
The infrastructure is the target
The bot that gets banned tomorrow was never the real problem — it's the referral network, the payment routing, and the generation infrastructure that make the next one trivial to launch. Detection has to be built for that reality: continuous, applied across formats, and integrated into the platforms where this content actually spreads.
See UncovAI's Detection Tools →This piece draws on public reporting by the Centre for Information Resilience, WIRED, The Guardian, NBC News, The Conversation, and Euronews. We've deliberately omitted operational details — bot names, links, technical architecture — that could help anyone locate or replicate these services.

