Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Summary
Cybersecurity agencies from the US, UK, and Netherlands have identified a Windows malware employed by Iran's intelligence service. This malware is utilized to conduct espionage against dissidents, journalists, and activists globally. It leverages the Telegram messaging app for command and control, enabling the exfiltration of emails and chat messages, capturing screenshots, and activating microphones for covert recording.
IFF Assessment
This article describes a malware used by a state-sponsored actor to spy on vulnerable populations, posing a direct threat to individuals and their work.
Defender Context
This report highlights the continued use of sophisticated malware by nation-state actors for targeted surveillance. Defenders should be aware of threat actor tactics, techniques, and procedures, particularly those involving the misuse of legitimate platforms like Telegram for command and control. Monitoring for unusual network activity and unusual process behavior on endpoints could help detect such campaigns.