
Iranian Intelligence Service Deploy Telegram-Controlled Malware for Global Surveillance
Cybersecurity authorities from the United States, the United Kingdom, and the Netherlands have issued a joint advisory warning of a Windows-based malware variant attributed to Iran's intelligence service. The malware, controlled via the Telegram messaging platform, is designed for surveillance of dissidents, journalists, and activists worldwide. Capabilities include exfiltrating emails and chat messages, capturing screenshots, and activating device microphones for recording. The advisory notes the malware likely spreads through social engineering but does not detail the specific infection vector. No patches are available; mitigation focuses on monitoring Telegram-based command-and-control traffic and enhancing endpoint security.