Interestana
Home/News/Iranian Hackers Use Telegram Malware to Spy on Dissidents
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Iranian Hackers Use Telegram Malware to Spy on Dissidents

Iranian Hackers Use Telegram Malware to Spy on Dissidents

Cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have jointly detailed a sophisticated Windows malware operation attributed to Iran's intelligence service. This malware is designed for espionage, targeting dissidents, journalists, and activists globally. Its primary control mechanism leverages the popular Telegram messaging application, allowing attackers to remotely command infected systems. The capabilities of this spyware include the exfiltration of sensitive data such as emails and chat messages from compromised devices. Furthermore, it can capture screenshots of user activity and activate the device's microphone for covert audio recording, providing attackers with comprehensive surveillance over their targets.

The joint advisory, issued by agencies including the US Cybersecurity and Infrastructure Security Agency (CISA), the UK's National Cyber Security Centre (NCSC), and the Netherlands's National Cyber Security Centre (NCSC-NL), highlights the persistent threat posed by Iranian state-sponsored cyber actors. The malware, referred to by researchers as 'Chainline' or 'MagicWeb' in previous analyses, operates by establishing a covert communication channel through Telegram. This method allows the attackers to send commands and receive stolen data without raising immediate suspicion, as Telegram is a widely used platform for communication. The malware's functionality extends to stealing browser cookies and credentials, further enabling unauthorized access to various online accounts and services.

This operation underscores a broader trend of nation-state actors employing readily available consumer technologies, like Telegram, to facilitate malicious cyber activities. The malware's modular design allows for flexibility and adaptation, potentially enabling the Iranian intelligence service to update its capabilities and evade detection. The agencies have provided technical details and indicators of compromise (IOCs) to assist organizations and individuals in detecting and defending against this threat. The advisory urges vigilance and the implementation of robust cybersecurity practices, including regular software updates, strong password policies, and multi-factor authentication, to mitigate the risks associated with such sophisticated espionage tools.

The identified targets—dissidents, journalists, and activists—suggest a deliberate effort by the Iranian regime to suppress dissent and monitor opposition voices both domestically and internationally. The ability to gain access to private communications, monitor online activities through screenshots, and record conversations poses a significant threat to freedom of expression and personal safety for those targeted. The coordinated release of this information by multiple international cybersecurity agencies signals the seriousness with which this threat is being regarded and aims to foster a collective defense against these advanced persistent threats originating from Iran.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next