Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists, Undermining Online Security for Vulnerable Groups

A disturbing trend has emerged in the world of cybersecurity, where Iranian hackers are using a novel technique to infiltrate the devices of dissidents, journalists, and activists. These cyber threats leverage the popular messaging app Telegram to distribute malware that allows attackers to spy on their targets with unprecedented ease.

The method involves creating custom Telegram bots that masquerade as genuine communication channels. Once the user interacts with the bot, usually by responding to a message or clicking on a link, the malware is downloaded onto their device. This malware can then grant the attacker full access to the victim’s device, including sensitive information such as login credentials and location data.

The affected individuals are primarily those who have been critical of the Iranian government or its policies. Human rights organizations and news outlets have reported that these cyber attacks have become increasingly sophisticated in recent months. It is believed that the Iranian hackers are exploiting the vulnerabilities of messaging apps like Telegram, which are often used by dissidents to communicate with each other without fear of interception.

The implications of this development go beyond the targeted groups, however. As more and more individuals rely on messaging apps for communication, the risk of being caught up in such cyber attacks grows. Even those who use these platforms innocently can fall victim to the malware, which can then be used by attackers to spread further or engage in other malicious activities.

The Iranian government has been accused of sponsoring these hacking operations, and some have questioned whether they are being carried out with tacit approval from state authorities. The consequences for those affected by such cyber attacks can be severe, including imprisonment, harassment, and even physical harm.

The use of Telegram-controlled malware represents a new frontier in the world of cyber espionage. As messaging apps become increasingly ubiquitous, it is crucial that users take steps to protect themselves from these threats. This includes being cautious when interacting with unfamiliar bots or links, using two-factor authentication whenever possible, and keeping software up to date with the latest security patches.

In light of this development, we advise readers to be vigilant when using messaging apps, especially if they have been critical of governments or engage in sensitive online activities. Staying informed about the latest cybersecurity threats and best practices can help protect against these types of attacks.


Source: The Hacker News — 2026-09-15