Monday, August 3, 2026

Policy & Regulation

FBI warns Iranian hackers are using Telegram for malware attacks

The FBI warns that Iranian government hackers are allegedly using Telegram to distribute malware and steal data from targets around the world, complicating cybersecurity defense efforts.

FBI warns Iranian hackers are using Telegram for malware attacks

On Friday, the FBI published an alert warning that Iranian government hackers are using the messaging platform Telegram to steal data from dissidents, opposition groups, and journalists around the world. According to the bureau, the hackers responsible for these attacks are allegedly working for Iran’s Ministry of Intelligence and Security (MOIS). The FBI stated that these attacks serve as an example of the Iranian government’s attempts to push the regime’s geopolitical agenda.

The cyber espionage campaign relies on a multi-stage social engineering process. First, the hackers contact their targets and pretend to be a known contact or technical support. The targets are then tricked into accepting a link to a malicious file masquerading as legitimate applications, such as Telegram or WhatsApp. Once the target installs this malware, the second stage of the attack connects the infected device to Telegram bots. This setup establishes command and control—a method used by attackers to remotely control infected devices—allowing the hackers to gain remote control of the victims’ devices to steal files, take screenshots, and record Zoom calls. Using Telegram in this manner is a common technique for hackers to hide malicious activity within legitimate network traffic, making detection more difficult for cybersecurity defenders.

In its alert, the FBI also referenced Handala, which it characterized as a pro-Iranian and pro-Palestinian fake hacktivist group, though the bureau noted it is not clear if the specific attacks in the alert were carried out by this group. The U.S. Justice Department has accused Handala of being a front for Iran’s government, specifically the MOIS. Handala previously claimed responsibility for a cyberattack on medical technology company Stryker, which resulted in wiping tens of thousands of employee devices. On Monday, Stryker filed an 8-K filing—a report of unscheduled material events—with the U.S. Securities and Exchange Commission, stating that the company is still recovering from the hack.

When reached for comment, Telegram spokesperson Remi Vaughn stated that the platform’s “moderators routinely remove any accounts found to be involved with malware.” An FBI spokesperson declined to provide further details on the situation, stating that the bureau had nothing additional to add.

Why it matters

The FBI alert highlights how state-sponsored actors are increasingly exploiting legitimate, widely-used platforms like Telegram to mask malicious activity. This tactic creates significant challenges for cybersecurity defenders attempting to distinguish between normal network traffic and espionage.