The Federal Bureau of Investigation has issued a warning about an ongoing cyber campaign in which hackers linked to the Iranian government are using the messaging platform Telegram to steal sensitive information from people around the world.

Targets include journalists and dissidents

According to the alert, the attackers are mainly focusing on dissidents, journalists and opposition groups.

In the early stages of the attack, they impersonate trusted contacts or technical support personnel. Victims are then persuaded to click on harmful links that are often disguised as legitimate applications such as WhatsApp or Telegram.

Malware enables remote access

Once a user installs the malicious software, the attackers are able to take control of the device. The malware connects to bots hosted on Telegram, which allows hackers to operate the system remotely.

Through this access, they can extract files, take screenshots and even record video calls, giving them significant control over the compromised device.

Use of Telegram helps evade detection

Cybersecurity experts have pointed out that the use of Telegram allows attackers to blend their activity with normal internet traffic. This makes it harder for security systems to detect unusual behaviour and identify the breach.

Links to Iranian intelligence and other groups

The FBI has associated these cyber operations with Iran’s Ministry of Intelligence and Security, stating that such activities are intended to support the country’s broader geopolitical objectives. The alert also referred to a pro-Iranian group known as Handala, although its direct role in these specific attacks has not been confirmed.

Recent cyber incidents raise concerns

Handala has also been connected to a recent cyberattack on Stryker, which led to disruption across thousands of employee devices. In response to such incidents, authorities in the United States have taken action against websites linked to these groups.

Response and safety measures

Telegram has stated that it actively removes accounts that are involved in harmful or illegal activity on its platform. Meanwhile, the FBI has urged users to stay alert, avoid clicking on suspicious links and follow strong cybersecurity practices to reduce the risk of falling victim to such attacks.

With Agency inputs