Iranian state-sponsored hackers have been using a sophisticated malware tool, controlled through the popular messaging app Telegram, to spy on dissidents and journalists in the region. The malicious software, which has been dubbed “TeleSpy,” allows its operators to remotely monitor the online activities of their targets, posing a significant threat to the security and privacy of those affected.
The use of Telegram as a control mechanism for TeleSpy is particularly noteworthy, as it highlights the growing trend of hackers leveraging legitimate communication platforms to carry out malicious operations. By using Telegram’s APIs, the attackers can issue commands to the malware, allowing them to remotely activate or deactivate its capabilities, including data exfiltration and screen capture.
The targets of this surveillance appear to be primarily individuals who have been critical of the Iranian government, including human rights activists, journalists, and opposition politicians. The hackers’ primary interest seems to be in gathering intelligence on these individuals’ online activities, including their browsing history, email communications, and social media interactions. This information can then be used for a range of purposes, from blackmail to more sinister forms of repression.
The malware itself is designed to operate undetected, using advanced techniques such as code obfuscation and encryption to evade detection by traditional security software. Once installed on a victim’s device, TeleSpy can remain dormant for extended periods, only activating when it receives a command from its Telegram-controlled operator. This makes it incredibly difficult for victims to even realize they have been compromised.
The use of Telegram-controlled malware is a concerning development, as it highlights the ease with which hackers can exploit legitimate communication platforms to carry out malicious activities. It also underscores the need for users to remain vigilant about their online security, particularly when using messaging apps that offer advanced features and APIs. Users should be aware of the risks associated with using such platforms, and take steps to protect themselves by using strong passwords, enabling two-factor authentication, and keeping software up-to-date.
In light of this threat, we recommend that users exercise extreme caution when using Telegram or any other messaging app that offers advanced features. By being aware of the potential risks and taking proactive measures to secure their devices and online activities, individuals can significantly reduce their exposure to TeleSpy and similar threats.
Source: The Hacker News — 2026-09-15