FBI says Iranian hackers are using Telegram to steal data in malware attacks
By Lorenzo Franceschi-Bicchierai
Published on March 23, 2026.
Iranian government hackers are using Telegram to steal data from dissidents, opposition groups, and journalists who oppose the regime, according to an FBI alert. The hackers pose as a legitimate contact or tech support, leading to a link to a malicious file masquerading as legitimate apps. Once the victim installs the malware, the hackers connect the infected victim with Telegram bots that allow them to remotely control their computer. These attacks are believed to be part of an effort by Iranian government hackers to advance their "geopolitical agenda". The FBI mentioned the pro-Iranian and pro-Palestine fake hacktivist group Handala, but it is unclear if these attacks were carried out by this group.
Read Original Article