The FBI warned that hackers linked to Iran’s Ministry of Intelligence and Security (MOIS) are using Telegram as command-and-control infrastructure in malware campaigns targeting Iranian dissidents, journalists, and opposition groups worldwide. The activity, observed since late 2023, relies on social engineering in which attackers impersonate trusted contacts or tech support and deliver malware disguised as legitimate apps such as Telegram, WhatsApp, or KeePass. Once installed on Windows systems, the multi-stage malware establishes persistence and connects to Telegram bots, allowing operators to steal files, capture screenshots and audio, record Zoom calls, compress data, and exfiltrate information.
U.S. authorities said the operations appear tailored to victims’ behavior, suggesting prior reconnaissance, and tied the activity to broader MOIS influence and disruption efforts. The FBI said the same ecosystem includes the fake hacktivist brands Handala Hack and Homeland Justice, which it linked to hack-and-leak operations that combine APT-style intrusions with disinformation and selective data leaks to cause reputational and political harm. The Justice Department has separately described Handala as an MOIS front involved in the recent Stryker attack, while the FBI has seized websites associated with Handala and Homeland Justice.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On March 23, 2026, the FBI issued a public warning that MOIS-linked hackers were using Telegram bots as command-and-control infrastructure in multi-stage malware attacks. The alert said the malware enabled surveillance, file theft, screenshots, audio capture, and exfiltration from victims' systems.
The FBI seized websites associated with the purported hacktivist groups Handala and Homeland Justice, which U.S. authorities said were linked to and controlled by MOIS. The action accompanied broader public attribution of the groups' operations to Iran.
The U.S. Justice Department accused Handala of operating as a front for Iran's MOIS and of carrying out the recent Stryker attack. This publicly advanced U.S. government attribution of the group's activity to Iranian intelligence.
In 2025, the FBI linked hack-and-leak activity by Handala Hack to MOIS and to Homeland Justice. The operations combined intrusion activity with selective data leaks and disinformation to cause reputational and political harm.
Since late 2023, Iran-linked actors associated with the Ministry of Intelligence and Security (MOIS) have run malware campaigns targeting Iranian dissidents, journalists, and opposition groups worldwide. The attacks used social engineering and trojanized apps such as Telegram, WhatsApp, and KeePass to infect Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecyberscoop.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.