← Blog · · df00tech

US, UK, and Dutch Agencies Detail Iranian Telegram-Controlled Spyware Targeting Dissidents

security-news campaign

Cybersecurity agencies in the United States, United Kingdom, and Netherlands have jointly detailed a Windows malware family that they attribute to Iran's intelligence service, used to surveil dissidents, journalists, and activists globally, according to The Hacker News.

What Was Reported

The joint advisory describes a Windows-based spyware tool that is controlled through the Telegram messaging app rather than traditional command-and-control infrastructure. Reported capabilities include exfiltrating a target's emails and chat messages, capturing screenshots, and activating the device microphone to record audio. The agencies attribute use of the malware to Iranian state intelligence operations targeting individuals rather than organizations.

Why It Matters for Defenders

This activity fits a pattern of state-linked actors abusing legitimate, widely-trusted messaging platforms for C2 to blend malicious traffic with normal application activity and complicate network-based detection. While the reported targeting is aimed at dissidents, journalists, and activists, the same tradecraft — commodity/messaging-app-based C2, credential and communications theft, and audio/screen surveillance — can be repurposed against employees at NGOs, media organizations, legal firms, and other entities that support or interact with at-risk individuals. Organizations with a global footprint or ties to human rights, journalism, or advocacy work should treat this as directly relevant to their threat model.

What Defenders Should Watch For

  • Unusual or unexpected outbound connections to Telegram API endpoints from hosts that have no legitimate business reason to use Telegram, especially from processes not associated with a Telegram client install.
  • Endpoint telemetry indicating unauthorized microphone activation or screenshot capture utilities running outside of expected user workflows.
  • Anomalous access to local email/chat client data stores (e.g., Outlook PST/OST files, browser-based webmail session data, messaging app databases) by non-standard processes.
  • Phishing or social-engineering lures targeting individuals connected to advocacy, journalism, or dissident communities, which is a common initial-access vector for this type of targeted spyware.
  • Review endpoint detection and response (EDR) coverage for behavioral detection of API-based C2 channels riding on legitimate cloud/messaging services, since signature-based network detection alone is unlikely to catch this.

This is a developing story and the technical indicators, full malware name, and detailed IOCs had not been fully digested at the time of this write-up. We will monitor for further technical reporting and update our detection content as more detail becomes available. Read the original coverage at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.