Cybersecurity & Privacy — 2026-03-24

FBI Warns Iranian Hackers Deploying Telegram Malware Against Dissidents, Journalists

The FBI issued an alert on Iranian government-connected groups deploying staged malware through Telegram, targeting Iranian dissidents, opposition journalists, and individuals perceived as threats to the regime. The malware masquerades as legitimate applications (Pictory, KeePass, Telegram) using Telegram bots for command and control. Attackers conduct pre-attack reconnaissance to match victims' 'pattern of life.' The Handala group, which claimed the recent Stryker medical device hack, leveraged intelligence gathered from these operations for hack-and-leak activities.

1 sources
  1. Iran-linked actors use Telegram as C2 in malware attacks on dissidents - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE