logo

Iran-Linked Hackers Use Messaging Platform to Target Dissidents and Journalists

ID: 10cda44a-859e-5b16-9723-206dfdb45efc

STIX ID: report--10cda44a-859e-5b16-9723-206dfdb45efc

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-05-05

Author: Samiksha Jain

...
...

**Executive Summary:** The FBI alert describes a targeted, multi-stage malware campaign attributed to Iran-linked MOIS actors that uses social engineering to deliver Windows implants which establish Telegram-based C2, record screen/audio, capture and exfiltrate files, and maintain persistence; the campaign targets dissidents and journalists and is linked to hack-and-leak activity (Handala Hack), increasing the risk of reputational and intelligence exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.