CuraSec

Act active

Iranian Intel Service Uses Telegram C2 Malware to Spy on Dissidents

2026-09-16 15:25 UTC · The Hacker News · read the source ↗ #iran-apt#telegram-c2#windows-malware
  • Engineer — Skip
  • SOC/IR — Act: Joint US/UK/NL advisory details active Windows malware using Telegram as C2 with email exfil, screenshot, and audio capture capabilities; pull the full advisory for IOCs and hunt for anomalous Telegram API calls or beacon traffic patterns in your estate since the advisory’s disclosure date.
  • Leader — Learn: Multi-government attribution of Iranian intelligence espionage tooling targeting journalists and dissidents; relevant background for risk context in media, NGO, or government-adjacent sectors, and useful framing for board discussions on geopolitical threat actors.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.