Iranian State-Sponsored Malware Exploits Telegram for Cyber Espionage Against Dissidents
Iranian state-sponsored hackers use Telegram-controlled malware to conduct cyber espionage against dissidents and journalists, exploiting phishing techniques to install malicious software on Windows systems. The malware, attributed to Iran's Ministry of Intelligence, enables data exfiltration, audio recording, and remote control through Telegram bots, with indicators of compromise including registry keys and network connections to cloud services.
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world.
The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
*** END OF TRANSMISSION ***