Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Executive Summary

U.S., U.K., and Dutch cybersecurity agencies have identified a Windows-based malware allegedly deployed by Iran’s intelligence services to surveil dissidents, journalists, and activists worldwide. The tool is controlled through the Telegram messaging app and can harvest emails and chat logs, capture screenshots, and activate the microphone for audio recording.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-15T16:29:51+00:00 - Category: threat-intel

Original Description: Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

"Some people are always grumbling because roses have thorns; I am thankful that thorns have roses."

— Alphonse Karr
Source: The Hacker News