Iranian Hackers Deploy Telegram-Controlled Malware Against Global Targets
State-backed actors are using a Windows malware controlled through Telegram to conduct surveillance on journalists, activists, and dissidents worldwide. The malware can capture communications, take screenshots, and activate microphones.
TL;DR
- US, UK, and Dutch agencies identified Windows malware used by Iranian intelligence.
- The malware communicates via Telegram and targets dissidents, journalists, and activists.
- Capabilities include stealing emails, chats, screenshots, and microphone recordings.
- Organizations should monitor for suspicious Telegram activity and unusual network behavior.
- Security teams must update endpoint detection and response rules to detect such tools.
Cybersecurity authorities from the US, UK, and the Netherlands have uncovered a sophisticated Windows-based malware operation linked to Iran's intelligence services. This malware is being used to conduct targeted surveillance against high-profile individuals such as dissidents, journalists, and political activists across multiple countries.
The malicious tool leverages the widely-used Telegram messaging platform for command and control operations, allowing attackers to remotely manage infected systems. Once installed, it grants extensive access to victim devices, enabling operators to extract sensitive data and monitor user activities without detection.
Malware Capabilities and Tactics
- The malware can exfiltrate emails and instant messaging conversations from compromised machines.
- It takes periodic screenshots of the victim’s desktop to gather visual intelligence.
- Remote activation of the device microphone allows for real-time audio surveillance.
- Communication with attacker infrastructure occurs through encrypted Telegram channels.
- Infection typically occurs via phishing emails or malicious document attachments.
Defensive Recommendations
- Organizations should implement strict network monitoring for anomalous Telegram API traffic.
- Endpoint protection platforms should be updated with signatures targeting known payloads.
- User education campaigns should emphasize risks associated with opening unsolicited documents.
- Privileged users and public figures should use application whitelisting and hardware security keys.
- Incident response teams should review logs for signs of unauthorized data extraction or screen capture tools.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.