Act
active
Iranian Intel Service Uses Telegram C2 Malware to Spy on Dissidents
- Engineer — Skip
- SOC/IR — Act: Joint US/UK/NL advisory details active Windows malware using Telegram as C2 with email exfil, screenshot, and audio capture capabilities; pull the full advisory for IOCs and hunt for anomalous Telegram API calls or beacon traffic patterns in your estate since the advisory’s disclosure date.
- Leader — Learn: Multi-government attribution of Iranian intelligence espionage tooling targeting journalists and dissidents; relevant background for risk context in media, NGO, or government-adjacent sectors, and useful framing for board discussions on geopolitical threat actors.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.