Cybersecurity & Privacy — 2026-03-23
FBI Issues Flash Warning: Handala Hackers Using Telegram Bots as C2 Infrastructure for Malware Campaigns
The FBI released FLASH-20260320-001 warning that Iran's MOIS cyber actors are using Telegram bot API as bidirectional command-and-control infrastructure to push Windows malware targeting Iranian dissidents, journalists, and opposition groups worldwide. The FBI formally attributed Handala Hack to MOIS, linking it to 'Homeland Justice.' This follows the March 11
2 sources
- FBI warns of Handala hackers using Telegram in malware attacks -
BleepingComputer - FLASH: Iran MOIS Cyber Actors Using Telegram for C2 -
FBI IC3