$ techbeacon▋
Malware

Iran‑linked malware leverages Telegram to monitor overseas activists and journalists

Iran‑linked malware leverages Telegram to monitor overseas activists and journalists

U.S., British and Dutch cybersecurity authorities have jointly disclosed a Windows‑based malware that they attribute to Iran's intelligence apparatus, describing it as a tool used to surveil dissidents, journalists and activists across the globe.

The malicious program operates through a command‑and‑control channel that relies on the popular messaging app Telegram. By embedding Telegram’s API within the code, the attackers can issue instructions, receive stolen data and update the payload without needing a traditional server infrastructure, complicating detection and attribution.

According to the joint report, the malware is deployed via phishing emails and malicious attachments that appear to originate from legitimate sources. Once executed on a victim’s computer, it records keystrokes, captures screenshots, and exfiltrates files to the Telegram‑based control server. The use of a widely trusted communication platform allows the operators to blend traffic with normal user activity, making network‑based defenses less effective.

Officials from the United States Cybersecurity and Infrastructure Security Agency, the United Kingdom’s National Cyber Security Centre and the Netherlands’ National Cyber Security Centre emphasized that the campaign reflects a broader trend of state‑sponsored actors exploiting everyday consumer services to conduct espionage. They warned that the targeting appears focused on individuals who are outspoken about Iran’s domestic policies or who report on regional issues.

The revelation arrives amid heightened scrutiny of Iran’s cyber capabilities, which have previously been linked to disruptive attacks on critical infrastructure and disinformation operations. By turning a ubiquitous messaging app into a covert control hub, the actors demonstrate a sophisticated understanding of both technical evasion techniques and the social dynamics of digital communication.

Security researchers recommend that organizations and at‑risk individuals adopt a layered defense strategy, including strict email filtering, regular software updates, and monitoring for anomalous Telegram traffic. They also advise the use of multi‑factor authentication and the isolation of sensitive activities from devices that may be exposed to unknown files.

While the three agencies have not disclosed the exact number of compromised systems, they indicated that the operation is ongoing and that additional victims may emerge as the malware continues to be distributed. The joint statement calls for international cooperation to disrupt the infrastructure supporting such campaigns and to hold state actors accountable for violations of international norms governing cyber‑espionage.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related