The story began when people using IPhone devices in Russia started seeing an alarming notice on their screens: “Unable to open the app ‘Telega’ because it contains malicious code. Delete this app from your device.” The message, which appears on iOS systems, forces the app to crash and sends users to a page that explains the purported security risk. For many users the interruption was sudden and confusing, and it prompted fresh questions about trust, privacy, and how third-party apps interact with official services.
Telega had soared in popularity after access to the official Telegram client was restricted in Russia, positioning itself as an alternative way to connect. Its creators described it as a fork of the official app — essentially a separate branch built from the original codebase — and pitched it as compatible with existing Telegram accounts. But independent IT experts who inspected the app warned that the client behaved in ways that went beyond what users expect from a typical messenger: it requested access to sensitive information and could allegedly monitor who communicates with whom and when.
What the warning says and what users experienced
The on-screen alert quoting “Unable to open the app ‘Telega’ because it contains malicious code. Delete this app from your device.” is the clearest signal most people received. When attempting to launch Telega, the application collapses and a dedicated information page appears describing the security classification. This is more than a mere crash report: it is a targeted notice that labels the software as containing malicious code, a term used by security analysts to describe programs that perform harmful or unauthorized actions. For users, the practical outcome has been loss of access to a favored client and an urgent decision about whether to delete the app.
Findings from researchers and the developer response
Security researchers who analyzed the app reported that Telega requested and obtained extensive permissions tied to personal data and messaging metadata, enabling potential tracking of contact patterns and timestamps. The investigators also pointed to infrastructure links suggesting an association with VK, a claim the app’s developers publicly denied. The developers maintain that Telega is an independent fork of Telegram, but analysts say the combination of data access and unusual network behavior raises red flags for user privacy and platform security alike.
Technical concerns unpacked
Experts highlighted several technical issues: unexpected permission scopes, data exfiltration vectors, and telemetry that could reveal social graphs. In plain terms, the app allegedly did more than show messages—it could have been collecting metadata about who messaged whom and when. Such capabilities are significant because even without reading message content, analysis of metadata can expose relationships and communication patterns. The description of these behaviors used the phrase personal data to cover names, contact lists, and timing information that could be sensitive in many contexts.
App store removal and unanswered questions
On April 9, Telega disappeared from the App Store. The official reason for the removal has not been disclosed, leaving a gap between the visible warning on devices and the storefront action. Users and investigators continue to debate whether the disappearance was initiated by the app’s developers, by Apple, or by another actor. Regardless of the cause, the removal has deepened concerns about third-party clients that arise when official services face restrictions, and it underscores the difficulty of verifying safety in rapidly adopted alternatives.
What users can do now
For people affected by the notice, the immediate practical advice is straightforward: follow the alert if you are uncomfortable with the risk and remove the app. Beyond deletion, users should review their account security settings for Telegram, revoke active sessions where possible, and monitor for unusual activity in linked services. Security professionals recommend relying on official clients distributed through verified channels when feasible, because unofficial forks can introduce unexpected behavior.
About this report and editorial transparency
At Meduza, we aim to be transparent about our use of technology in producing journalism. This article was written by a human reporter and translated from Russian using an AI model configured to follow our editorial standards; every draft is reviewed by a human editor before publication. If you spot any errors in this translation, please contact us at [email protected]. To receive Meduza’s exclusive English coverage, consider subscribing to our newsletter for direct delivery of translated stories and updates.


