logo

FBI says Iranian hackers are using Telegram to steal data in malware attacks

ID: ec3a64c4-11e3-5c1a-8419-18c6bfd98672

STIX ID: report--ec3a64c4-11e3-5c1a-8419-18c6bfd98672

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

An FBI alert warns that Iranian government-linked hackers are using social-engineering lures and malicious installers masquerading as legitimate apps (e.g., Telegram/WhatsApp) to deploy remote-access malware that connects infected systems to Telegram bots. The actors — allegedly linked to Iran’s MOIS and to groups like Handala — remotely control devices to exfiltrate files, capture screenshots, and record calls, targeting dissidents, opposition groups, and journalists globally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.