Cybersecurity & Privacy — 2026-03-23
FBI Warns of Iranian Handala Hackers Using Telegram for Malware Distribution and Data Exfiltration
The FBI issued an advisory warning of Iranian hacktivist group Handala exploiting Telegram for malware distribution campaigns. Handala previously orchestrated the Stryker medical device company cyberattack on March 11 that compromised over 200,000 servers across 79 countries. The FBI and CyberScoop reporting detail how Handala uses Telegram channels to coordinate attacks and distribute malware targeting opponents of the Iranian regime. The advisory coincides with broader Iran-linked cyber activity including the Trivy supply chain compromise.
Analysis
Handala group was previously tracked in the March 17 Soufan Center cyber brief on Iranian asymmetric leverage. FBI warning elevates this from think-tank assessment to official USG threat notification, suggesting operational intelligence on active targeting.
1 sources
- FBI warns of Russian, Iranian cyber activity involving messaging platforms - The Record
View in full brief →