NewsTradingSentimentCalendarCommunityBriefing
Tech

Iranian Spies Use Telegram to Control Malware Targeting Journalists

By Tech Desk · 2026-09-15 · 2 min read
A dark, shadowy figure stands behind a glowing computer monitor in a dimly lit room
Illustration: Tradingbird

A new joint advisory reveals how Iranian intelligence uses a messaging app to remotely spy on dissidents and journalists, turning personal devices into surveillance tools.

Cybersecurity agencies in the United States, United Kingdom, and Netherlands have identified a sophisticated malware campaign targeting Iranian dissidents, journalists, and activists. The tool, attributed to Iran's Ministry of Intelligence and Security, is controlled remotely via the Telegram messaging app. This setup allows attackers to bypass traditional network security by using a common consumer platform for command and control.

The joint advisory, published on September 15, details how the software can copy emails, capture screenshots, and activate microphones on infected Windows computers. While the primary targets are those opposing the Iranian government, the FBI has warned that anyone deemed of interest could be at risk. This creates a persistent threat for independent media and human rights workers operating outside Iran.

Disguised files initiate the infection

The attack typically begins with social engineering, where attackers pose as known contacts or tech support to build trust. They then send a file disguised as legitimate software, such as a password manager, antivirus tool, or even medical scan results. When the victim opens the file, a convincing fake interface appears, masking the installation of the actual spyware in the background.

The malware is designed to persist on the system by adding itself to Windows registry keys, ensuring it restarts automatically upon login. It also instructs Microsoft Defender to ignore specific folders, effectively blinding the built-in antivirus to its presence. This technical maneuver allows the spyware to remain hidden while it collects sensitive data.

Telegram bots act as command channels

Once installed, the malware connects to a unique Telegram bot assigned to each victim. This bot serves as the primary link for the attackers to issue commands and retrieve stolen data. By using a popular messaging app, the attackers leverage trusted infrastructure to move data out of the target’s computer, often via cloud storage services, making detection more difficult for standard network monitoring tools.

The FBI and NCSC note that this method isolates each victim’s data, preventing cross-contamination that might alert other targets. The capability extends to deleting files or wiping the computer entirely if the attackers wish to destroy evidence. This level of control transforms a standard Windows PC into a fully managed surveillance device.

Stolen data threatens personal safety

The danger extends beyond data theft to physical security. Collected information, including location data, contact lists, and daily routines, has been posted on pro-Iranian leak sites. These sites have been used to harass victims and, in some cases, call for violence against dissidents and journalists. The US Justice Department recently seized four such sites, highlighting the direct link between cyber espionage and real-world threats.

As reported by The Hacker News, this campaign underscores a broader trend of state-sponsored cyber operations aimed at suppressing opposition. The trade-off for users relying on common messaging apps is increased exposure to targeted attacks that bypass standard corporate security measures, particularly on personal devices.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A large, windowless industrial building with rows of ventilation fans on the side, standing in a suburban landscape
    Illustration: Tradingbird

    Poway Council Prepares Ban on AI Data Centers

    A small California city is moving to block the construction of artificial intelligence facilities, citing severe risks to local water supplies, power grids, and air quality. This decision represents a significant shift in how communities are managing the physical footprint of the digital economy.

    2026-09-15
  • A sleek white electric aircraft parked on a tarmac next to a large industrial charging station with thick cables coiled neatly on the ground.
    Illustration: Tradingbird

    Texas Leads Push for Shared Electric Air Taxi Charging Network

    A new consortium aims to standardize charging infrastructure for electric air taxis across major Texas airports, seeking to solve the fragmentation problem in eVTOL support systems.

    2026-09-15
  • A heavy iron padlock resting on a polished wooden desk surface
    Illustration: Tradingbird

    Treasury Rejects AI Liability Waivers

    Treasury Secretary Scott Bessent urged lawmakers to reject requests from AI developers for legal immunity, arguing that holding creators accountable is the most effective way to ensure technological safety.

    2026-09-15