The FBI warned that cyber actors working on behalf of Iran’s Ministry of Intelligence and Security (MOIS) used Telegram as command-and-control infrastructure in a long-running malware campaign targeting Iranian dissidents, anti-regime journalists, and other opposition figures around the world. In FLASH-20260320-001, the bureau said the activity has been ongoing since at least fall 2023 and relied on social engineering and victim-tailored lures to deliver multi-stage Windows malware disguised as legitimate applications including Telegram, KeePass, WhatsApp, and Pictory.
According to the alert, the second-stage implant enabled persistent remote access and bidirectional communications through Telegram infrastructure, allowing operators to steal files, compressed archives, screen captures, and audio from infected systems. The FBI also linked some July 2025 hack-and-leak activity claimed by Handala Hack to malware used in the campaign and assessed that Handala Hack is connected to Homeland Justice, which it described as another MOIS-operated online entity, underscoring Iran’s broader use of proxy personas and cyber operations to combine espionage, data theft, and information operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-20, the FBI issued FLASH-20260320-001 warning that MOIS-linked cyber actors were using Telegram as command-and-control infrastructure to deliver and operate multi-stage malware. The alert described the malware’s persistent remote-access and data-theft capabilities, including collection of screen captures, audio, files, and compressed archives.
In July 2025, some hack-and-leak activity publicly claimed by Handala Hack was linked by the FBI to malware used in the broader MOIS-associated campaign. The FBI also assessed that Handala Hack is connected to Homeland Justice, another online entity operated by MOIS.
Cyber actors working on behalf of Iran’s Ministry of Intelligence and Security began a malware campaign targeting Iranian dissidents, anti-regime journalists, and other opposition figures worldwide. The activity, active since at least fall 2023, used social engineering and trojanized Windows applications masquerading as tools such as Telegram, KeePass, WhatsApp, and Pictory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.