logo

Iran-linked actors use Telegram as C2 in malware attacks on dissidents

ID: 8d5e7c4f-e9e2-5f2f-8fe0-6edb9a673fe0

STIX ID: report--8d5e7c4f-e9e2-5f2f-8fe0-6edb9a673fe0

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The FBI alert describes Iran-linked Ministry of Intelligence and Security (MOIS) cyber campaigns that employ social engineering and multi-stage malware—masquerading as legitimate apps—to compromise Windows systems of dissidents, journalists, and opposition figures. Infected hosts install persistent implants that use Telegram bots (api.telegram.org) for bidirectional C2, enabling screen and audio capture, file collection/compression, and exfiltration; the report includes example malware filenames and urges standard mitigations (patching, trusted sources, AV, MFA, reporting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.