IND refers to "indistinguishability"; it is the property of not being able to pick a matching plaintext/ciphertext pair out of a lineup of ciphertexts.
CCA stands for Chosen Ciphertext Attacks, and refers to the class of attacks where the cryptanalyst alters ("chooses") the ciphertext before it's decrypted by the victim, and is then able to learn things from the victim's behavior. (There's also CCA2, in which the attacker gets feedback from the victim on a single piece of ciphertext, over and over again.)
TLS's Mac-then-encrypt CBC was known not to be IND-CCA secure, and a few years later Thai Duong and Juliano Rizzo turned that property into BEAST. Then there was CRIME, then Lucky13, and finally TLS MtE CBC had to be put to sleep.
The easiest way to lose IND-CCA security is to fail to MAC your ciphertext. This is such a common flaw that Moxie Marlinspike, a co-author of TextSecure/Signal, which you should use in preference to Telegram, named it "the cryptographic doom principle".
This paper is a building block for a much more significant attack, which is the author's masters thesis: