CuraSec

tag: Telegram-C2 · 1 items

2026-09-16 · The Hacker News · source ↗ #iran-apt#telegram-c2#windows-malware
  • Engineer — Skip
  • SOC/IR — Act: Joint US/UK/NL advisory details active Windows malware using Telegram as C2 with email exfil, screenshot, and audio capture capabilities; pull the full advisory for IOCs and hunt for anomalous Telegram API calls or beacon traffic patterns in your estate since the advisory’s disclosure date.
  • Leader — Learn: Multi-government attribution of Iranian intelligence espionage tooling targeting journalists and dissidents; relevant background for risk context in media, NGO, or government-adjacent sectors, and useful framing for board discussions on geopolitical threat actors.