Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • FBI: Iranian hackers targeting opponents with Telegram malware  – CyberScoop
AttackFeed by Joe Wagner | FBI: Iranian hackers targeting opponents with Telegram malware  - CyberScoop

FBI: Iranian hackers targeting opponents with Telegram malware  – CyberScoop

Posted on March 23, 2026 By Tim Starks
Attack Feeds

Iranian government-connected groups are deploying malware via the Telegram messaging app, taking aim at dissidents and other opponents of Tehran around the world, the FBI said in an alert Friday.

The FBI said attackers linked to the Ministry of Intelligence and Security are behind the campaign, which stretches back to 2023. The bureau is escalating the alert now, though, because of the conflict between Iran and a U.S.-Israel alliance, it states.

“The observed victim profile included Iranian dissidents, journalists opposed to Iran, members of organizations with beliefs counter to Government of Iran narratives, and other individuals Iran perceives as a threat to the Iranian government, However, the malware could be used to target any individual of interest to Iran.” the alert reads. “This malware resulted in intelligence collection, data leaks, and reputational harm against the targeted parties.” 

Handala — an Iranian pro-Palestinian group that claimed credit for the hack on medical device maker Stryker this month — used information it gathered from hacking dissidents to carry out a hack-and-leak campaign in 2025, the FBI assesses. (Stryker sent a notice to the Securities and Exchange Commission Monday that provides an update on the incident.)

While U.S. officials say they haven’t seen any major increase in cyberattacks out of Iran since the conflict began, experts have noted it could be weeks before patterns emerge.

Telegram is a popular communications channel in Iran. Iranian hackers frequent Telegram to discuss planned attacks. On the other hand, the Islamic Revolutionary Guard Corps has also issued warnings to its populace that they could face prosecution if they’re members of Telegram-based opposition channels, IranWire reported last week.

The FBI said from the malware samples it examined, the scheme begins with hackers masquerading as apps like Pictory, KeePass and Telegram. The hackers configure command and control using a Telegram bot.

To gain initial access, the hackers seek to manipulate victims by posing as someone they know or as tech support for a social media platform. They then trick the victims into accepting a file transfer, which then launches the malware.

“Based on multiple observations, stage 1 of the malware appeared to be tailored to the victim’s pattern of life to increase likelihood of victim downloading the malware, which indicates the Iranian cyber actors likely performed target reconnaissance prior to engaging with the victim,” the FBI said.

The FBI alert is the latest in a series of government warnings about attackers using messaging apps to carry out their objectives.

Telegram spokesperson Remi Vaughn said in an emailed response: “Bad actors can and do use any available channel to control malware, including other messengers, email or even direct web connections. While there is nothing unique about the use of Telegram to control software, moderators routinely remove any accounts found to be involved with malware.”

The post FBI: Iranian hackers targeting opponents with Telegram malware appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: North Korean Hacker Lands Remote IT Job, Caught After VPN Slip  – Hackread – Cybersecurity News, Data Breaches, AI and More
Next Post: State officials, election experts question California sheriff’s seizure of ballots  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | State officials, election experts question California sheriff’s seizure of ballots  - CyberScoop
Attack Feeds
State officials, election experts question California sheriff’s seizure of ballots  – CyberScoop
March 23, 2026
Attack Feeds
Smashing Security podcast #457: How a cybersecurity boss framed his own employee  – GRAHAM CLULEY
March 4, 2026
AttackFeed by Joe Wagner | Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  - CyberScoop
Attack Feeds
Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop
April 3, 2026
AttackFeed by Joe Wagner | GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension  - The Hacker News
Attack Feeds
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension  – The Hacker News
May 21, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.