- Iran’s Ministry of Intelligence and Security has been running an active spyware campaign since late 2023, using Telegram’s own bot system as hidden infrastructure to remotely control malware on victims’ devices.
- FBI investigators linked the same malware toolkit to the “Handala Hack” group, which leaked data stolen from critics of the Iranian government and previously hit American healthcare giant Stryker with a destructive cyberattack.
- A new Check Point Research report reveals Telegram removed over 43.5 million channels and groups in 2025, yet cybercriminals largely stayed put, adapted their tactics, and kept the platform as the undisputed headquarters of underground operations worldwide.
The FBI has issued a fresh warning that Iranian state-backed hackers are running an active spyware operation, and they are using Telegram to pull the strings.
The FBI FLASH bulletin identifies the threat actors as cyber operatives working directly on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Their targets are not corporations or government servers.
They are going after journalists, political dissidents, and opposition figures, individuals the Iranian government considers threats, hitting Windows devices with tailored malware and running everything through Telegram’s own bot infrastructure.
How Iranian Hackers Hijacked Telegram’s Own System Against Its Users
The attackers do not announce themselves. They approach targets through popular messaging platforms, impersonating trusted contacts or posing as technical support staff.
Once they build enough trust, they push victims into downloading malicious files disguised as familiar tools, doctored versions of apps like KeePass, WhatsApp, or Telegram itself.
After a victim runs the file, the initial payload drops a persistent second-stage implant deep into the system. That implant reaches out to attacker-controlled Telegram bots using the platform’s official API, effectively converting a mainstream messaging tool into a covert command-and-control channel.
The attackers then gain full remote access, pulling files, capturing screenshots, and monitoring activity. Some variants even record audio and screen content during Zoom sessions.
FBI investigators identified several malicious components the campaign uses, MicDriver.exe, MsCache.exe, and RuntimeSSH.exe, each handling separate tasks like data collection, compression, and transmission.
The malware also digs into Windows Registry entries and deploys PowerShell-based techniques to slip past security warnings.
The attackers clearly do their homework; each initial payload carries victim-specific customization, suggesting they run targeted reconnaissance before striking.
FBI Ties the Campaign to the Handala Hack Group and a July 2025 Leak Operation
The FBI did not stop at describing the malware. Investigators connected key elements of the campaign to the “Handala Hack” persona, the same group that claimed responsibility for a July 2025 leak operation that exposed data belonging to critics of the Iranian government. The FBI confirmed that the leaked data came from the very same malware toolkit described in the bulletin.
Handala carries a track record that goes beyond data theft. The group has previously launched destructive wiper malware attacks and carried out a damaging cyberattack against Stryker, an American healthcare technology company.
The FBI’s findings reveal that this latest spyware campaign is not an isolated event; it is part of an ongoing, state-linked offensive that blends surveillance, data theft, and public pressure operations into a single coordinated strategy.
Telegram Blocks Millions of Channels, But Cybercriminals Refuse to Leave
The FBI bulletin also lands as fresh evidence of a deeper platform problem Telegram cannot seem to solve. A Check Point Research report shows Telegram removed more than 43.5 million channels and groups throughout 2025, a dramatic enforcement surge that began in February and hit carding communities, hacking groups, and fraud networks hardest between February and April.
Despite those numbers, Check Point found no meaningful migration away from the platform. Comparing invite links shared across underground communities puts Telegram at 3 million mentions, dwarfing Discord at 153,000, Signal at 8,000, and Element at 6,000.
Threat actors simply adjusted. They now exploit Telegram’s “Request to Join” feature to block automated monitoring, plant compliance disclaimers to create a false appearance of legitimacy, and pre-build backup channels so their communities can regroup within hours of a takedown.
Telegram’s enforcement has clearly grown stronger, but cybercriminals have grown smarter with it. The platform remains the industry standard for threat actors, state-sponsored or otherwise, and the FBI’s latest bulletin makes that reality impossible to ignore.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...