HomeSecurityIranian hackers target journalists and dissidents via Telegram

Iranian hackers target journalists and dissenters via Telegram

The Iran Telegram malware campaign has once again drawn attention to how state-backed cybercriminals are adapting their tactics by incorporating them into widely used digital platforms. In a recent alert, the Federal Bureau of Investigation (FBI) revealed that cybercriminals affiliated with Iran’s Ministry of Intelligence and Security (MOIS) are using Telegram as a command and control (C2) infrastructure to deploy malware.

See also: Handala: New domain a few hours after seizure by the FBI

 Iran Telegram
Iranian hackers target journalists and dissenters via Telegram

The campaign specifically targets Iranian dissenters, journalists and individuals or groups considered opposed to the Iranian government. According to the FBI, these operations have led to information gathering, data leaks and reputational damage, indicating that the intent goes beyond simple access and leans toward continuous monitoring and influence.

The Iran Telegram malware activity dates back at least to the fall of 2023, with multiple malware variants having been found targeting Windows systems. The victims' profile is not random. It is clearly defined, focused on individuals whose views or connections are considered a threat by the Iranian government.

However, the FBI also notes that the malware can be used against any person of interest, indicating that the capability is broader than the observed targets.

What stands out is the level of preparation. The malicious software is not just developed, but is tailored. The attackers seem to study their targets in advance, customizing the lures to increase the chances of success. This shows a deliberate and information-based approach rather than opportunistic attacks.

The FBI describes a structured, multi-layered malware framework that combines deception with persistence. Attackers approach their targets via messaging platforms, posing as trusted contacts or even technical support. Victims are persuaded to download files presented as legitimate applications.

See also: Iran was preparing cyberattacks before Epic Fury

Iranian hackers target journalists and dissenters via Telegram

These files often appear as commonly used software, including messaging tools or utilities, making them harder to dispute. All collected data is routed through Telegram's infrastructure, enhancing its role as a central element of the attack chain.

The FBI also links this campaign to the cyber entity “Handala Hack,” which claimed responsibility for a hack-and-leak operation in 2025 that targeted individuals critical of Iran. The agency estimates that some of the leaked data was obtained using malware associated with this campaign. Handala Hack is known for phishing, data theft, extortion, and destructive cyber activities, including the use of wiper malware.

Additionally, the group is linked to “Homeland Justice,” another entity believed to be operated by MOIS cybercriminals.

This reflects a broader pattern where technical intrusions are followed by public data exposure. The goal is not only access, but also damage to reputation and politics through controlled release of information.

What makes the Iran Telegram malware campaign particularly concerning is its simplicity combined with precision. It relies heavily on human interaction rather than technical exploits. It uses trusted platforms instead of suspicious infrastructures. It focuses on specific individuals rather than mass attacks. This combination makes detection more difficult and increases the likelihood of success.

See also: DarkSword: Hackers target iOS 18 via infected links

UNC1860

Despite the complexity of the campaign, the FBI's recommendations remain based on basic cybersecurity practices:

  • Be cautious of unexpected messages, even from known contacts
  • Avoid downloading files from unverified sources
  • Keep systems updated with the latest software updates
  • Use strong passwords and enable multi-factor authentication
  • Run antivirus or anti-malware tools regularly
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS