Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Telegram Applied for .gram: What It Means for the Threat Landscape
Aug 19, 2026
8 Mins Read
Aug 20, 2026
Moon
Summarize with:

Telegram Applied for .gram: What It Means for the Threat Landscape

TL;DR

  • Telegram has applied for the .gram top-level domain through ICANN’s 2026 round. If approved, Telegram usernames could become web-addressable domains with AI-generated websites.
  • This creates a new namespace for phishing, impersonation, and threat actor self-promotion, operated by a platform already deeply embedded in the threat landscape.
  • Telegram would become the registry operator, making it the gatekeeper for abuse reports and takedowns across potentially a billion domains.
  • The July 2026 t.me serverHold incident showed what happens when Telegram depends on someone else’s domain infrastructure. Owning .gram would flip that dynamic but also transfer compliance liability onto Telegram.
  • Security teams should start monitoring the ICANN approval process, treat Telegram username squatting as a brand protection issue, and prepare to add .gram to their detection pipelines.

On August 18, Pavel Durov announced that Telegram has applied to ICANN for the .gram top-level domain. If this application is approved, Telegram’s users could get a second-level domain connected to their username. Also, users would be able to create interactive websites through Telegram using a single prompt.

Pavel Durov’s tweet announcing that Telegram has applied to ICANN for the .gram top-level domain

Pavel Durov’s tweet announcing that Telegram has applied to ICANN for the .gram top-level domain

A New Namespace, Built on an Existing Threat Ecosystem

Telegram already has a central role in the threat landscape. Threat actors use Telegram’s Bot API a lot for credential theft and as a C2. And alongside these, more threat actors are using Telegram as a place to brag about their activities, almost like a storefront.

We don’t know the details of this possible feature, but a .gram TLD can extend this ecosystem in two ways:

  • It can give threat actors a more visible and polished way to advertise their operations. We can see an increase in leak sites, service offerings, and more. At the same time, this will create another area for analysts to investigate.
  • Every Telegram username can turn into a domain. The websites can contain any type of content generated with a single prompt. That means threat actors can deploy phishing pages, fake login screens, or malware delivery sites with no infrastructure setup and no technical skill.

Impersonation at the DNS Level

Another issue is related to the brand protection topic. Telegram is pretty popular in certain parts of the world, but not all. Companies have their social media accounts and websites tied to their name in one way or another. But many of them lack any presence in Telegram. Whoever holds @paypal on Telegram would control paypal.gram. Whoever holds @microsoft would control microsoft.gram.

Today, “Telegram username squatting” is not important for many brands. Under .gram, it can become an impersonation vector that resolves in browsers and shows up in search results. If approved, .gram would add another area that security teams need to monitor.

Strengthen Brand Protection Against Emerging Threats

SOCRadar Brand Protection helps organizations monitor their digital presence for phishing, impersonation, fake accounts, and other forms of brand abuse. It provides actionable alerts that help security teams investigate emerging threats and respond before they damage customer trust or brand reputation.

SOCRadar Brand Protection helps security teams detect, investigate, and respond to online brand abuse.

SOCRadar Brand Protection helps security teams detect, investigate, and respond to online brand abuse.

Telegram as Registry Operator: The t.me Precedent

In July 2026, Telegram experienced what can go wrong when your domain infrastructure is controlled by someone else.

The .me registry placed t.me on serverHold after a U.S. Treasury OFAC sanctions designation listed a Telegram channel under t.me as part of the sanctioned infrastructure of a VPN service. The hold took Telegram’s short links offline worldwide for roughly 19 hours. Telegram could not directly reverse the action because serverHold was applied at the registry level, outside Telegram’s control. Telegram had to work with the registry to resolve the issue.

The July 2026, the “t.me” outage probably raised a question at Telegram HQ about registry-level control. When a registry operator takes action against a domain, it can affect services built across that domain’s namespace, and Telegram, as the registrant of “t.me”, did not operate the “.me” registry itself and therefore did not control registry-level decisions affecting the domain.

But a “.gram” TLD would put Telegram in a different position. As the registry operator, Telegram would manage the `.gram` registry and its authoritative zone. It would play a central role in decisions on abuse reports, domain suspensions, registration policies, and the disclosure of registration data, subject to its ICANN contractual obligations and applicable law. There would be no separate registry operator to manage the “.gram” namespace.

Authority flow showing today’s situation and what can happen in the future

Authority flow showing today’s situation and what can happen in the future

This creates a question for defenders. Today, phishing domains can be reported through established channels involving registrars and, where relevant, registries. ICANN’s 2024 DNS Abuse amendments require contracted parties to take prompt and appropriate mitigation action when they receive actionable evidence of DNS Abuse. The rules, however, do not define a fixed response-time SLA.

If a phishing domain such as `yourbank.gram` were registered, Telegram’s abuse response process would become a central part of the mitigation path. Its staffing, operational procedures, and response times could influence how quickly malicious domains are addressed.

The proposed model could also create a significant scale challenge. Existing brand TLDs are generally used within controlled registration environments. A “.gram” namespace designed for broad, potentially automated use by a large platform user base could create a very different operational model. If registration is widely available and content or domain creation is highly automated, abuse handling would need to operate at a scale beyond that of many existing brand TLDs.

The broader issue is related to control and accountability. A platform that also operates its own TLD can bring registration, distribution, and abuse response closer together. For defenders, the key question would be how transparent, responsive, and scalable that registry’s abuse mitigation process proves to be in practice.

Abuse Trend for New gTLDs

The track record of new generic top-level domains adds another angle here. Research from Interisle Consulting found that new gTLDs hold roughly 12% of the market but account for nearly half of all reported cybercrime domains and well over half of maliciously registered cybercrime domains.

We can see that abuse concentrates early in a new TLD. Attackers watch launch calendars and register infrastructure quickly once new extensions open for public registration. This is an important indicator for defenders to watch.

What Defenders Should Do Now

The .gram application is still early-stage. That said, CTI teams can start preparing now.

  • Monitor the ICANN applicant list when it drops, and track .gram through the approval process.
  • Begin treating Telegram username intelligence as a brand protection input, especially for high-value impersonation targets.
  • Once .gram goes live, prioritize early monitoring of the namespace in URL filters, blocklists, and phishing detection pipelines, because the detection gap will be widest in those first weeks.

And pay attention to how Telegram handles its registry obligations around abuse reporting and takedowns, because that will set the tone for how useful or how painful this new TLD becomes for the security community.

FAQ

What is .gram? .gram is a new top-level domain that Telegram has applied for through ICANN. If approved, it would work like .com or .net, with Telegram operating the registry. Users could get domains like yourname.gram tied to their Telegram username.

Is .gram approved? No. Telegram submitted the application before ICANN’s August 12, 2026 deadline. ICANN is expected to publish the full applicant list around late October 2026. The review and approval process can take over a year.

What happened with t.me in July 2026? The .me registry placed Telegram’s t.me domain on serverHold after a U.S. OFAC sanctions filing listed a Telegram channel as infrastructure of a sanctioned VPN service. Every t.me short link went offline for roughly 19 hours. Telegram could not reverse it on its own.

How would .gram change things for Telegram? Telegram would go from being a domain registrant (subject to another registry’s decisions) to being the registry operator itself. That means Telegram would control abuse response, takedown decisions, and registration policies for the entire .gram namespace.

Why does this matter for security teams? A .gram TLD could create a new surface for phishing, brand impersonation, and threat actor operations, all backed by AI-generated content and tied to a platform with a large existing threat footprint. Security teams would need to add .gram to their monitoring scope for URL filtering, blocklists, and brand protection.