Operations & Intelligence Failures — 2026-03-23
FBI Issues FLASH Alert: Iranian MOIS Handala Group Deploying Telegram-Based Malware Against Dissidents
The FBI published IC3 FLASH 260320 warning that Iranian MOIS-linked Handala hackers are using Telegram bot infrastructure for command-and-control in malware campaigns targeting Iranian dissidents, journalists, and opposition figures globally. Attackers impersonate legitimate apps (Pictory, KeePass, Telegram) to deliver Windows malware enabling screenshot capture and file exfiltration. The campaign dates to 2023 with gathered intelligence used in Handala's 2025 hack-and-leak operations and the March 2026 Stryker medical device breach. DOJ previously seized four Handala/Homeland Justice websites and attributed both groups to MOIS.
1 sources
- FBI: Iranian hackers targeting opponents with Telegram malware - CyberScoop
View in full brief →