Iranian Spies Use Telegram to Control Malware Targeting Journalists

A new joint advisory reveals how Iranian intelligence uses a messaging app to remotely spy on dissidents and journalists, turning personal devices into surveillance tools.
Cybersecurity agencies in the United States, United Kingdom, and Netherlands have identified a sophisticated malware campaign targeting Iranian dissidents, journalists, and activists. The tool, attributed to Iran's Ministry of Intelligence and Security, is controlled remotely via the Telegram messaging app. This setup allows attackers to bypass traditional network security by using a common consumer platform for command and control.
The joint advisory, published on September 15, details how the software can copy emails, capture screenshots, and activate microphones on infected Windows computers. While the primary targets are those opposing the Iranian government, the FBI has warned that anyone deemed of interest could be at risk. This creates a persistent threat for independent media and human rights workers operating outside Iran.
Disguised files initiate the infection
The attack typically begins with social engineering, where attackers pose as known contacts or tech support to build trust. They then send a file disguised as legitimate software, such as a password manager, antivirus tool, or even medical scan results. When the victim opens the file, a convincing fake interface appears, masking the installation of the actual spyware in the background.
The malware is designed to persist on the system by adding itself to Windows registry keys, ensuring it restarts automatically upon login. It also instructs Microsoft Defender to ignore specific folders, effectively blinding the built-in antivirus to its presence. This technical maneuver allows the spyware to remain hidden while it collects sensitive data.
Telegram bots act as command channels
Once installed, the malware connects to a unique Telegram bot assigned to each victim. This bot serves as the primary link for the attackers to issue commands and retrieve stolen data. By using a popular messaging app, the attackers leverage trusted infrastructure to move data out of the target’s computer, often via cloud storage services, making detection more difficult for standard network monitoring tools.
The FBI and NCSC note that this method isolates each victim’s data, preventing cross-contamination that might alert other targets. The capability extends to deleting files or wiping the computer entirely if the attackers wish to destroy evidence. This level of control transforms a standard Windows PC into a fully managed surveillance device.
Stolen data threatens personal safety
The danger extends beyond data theft to physical security. Collected information, including location data, contact lists, and daily routines, has been posted on pro-Iranian leak sites. These sites have been used to harass victims and, in some cases, call for violence against dissidents and journalists. The US Justice Department recently seized four such sites, highlighting the direct link between cyber espionage and real-world threats.
As reported by The Hacker News, this campaign underscores a broader trend of state-sponsored cyber operations aimed at suppressing opposition. The trade-off for users relying on common messaging apps is increased exposure to targeted attacks that bypass standard corporate security measures, particularly on personal devices.






