logo

FBI warns of Russian, Iranian cyber activity involving messaging platforms

ID: 1432178b-26e8-50b9-a3c2-d290d74fc1cd

STIX ID: report--1432178b-26e8-50b9-a3c2-d290d74fc1cd

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-05-01

...
...

The FBI and CISA issued alerts about two active, nation-state campaigns: Russian actors are phishing users of Signal and other messaging apps to add linked devices or fully takeover accounts—compromising messages and contact lists—while Iran’s MOIS-linked group ‘Handala Hack’ distributes Windows malware that masquerades as legitimate apps and uses Telegram bots as C2 to exfiltrate files, capture screens/audio, and monitor targeted dissidents and journalists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.