Image: from Dark Web Intelligence X @DailyDarkWeb
By Open Chronicle Staff | Friday, March 21, 2026
WASHINGTON D.C. — The FBI has issued an urgent “FLASH” alert to national security partners and the private sector, warning that the Iranian Ministry of Intelligence and Security (MOIS) is aggressively using the messaging platform Telegram as a command-and-control (C2) hub for global cyber-espionage and domestic repression.
The federal warning, released Friday, details a sophisticated malware campaign designed to infiltrate the devices of Iranian dissidents, journalists, and international organizations opposed to the Tehran regime. The alert comes as geopolitical tensions reach a fever pitch following weeks of kinetic conflict between the U.S., Israel, and Iran.
Telegram as a Digital Weapon
According to the FBI, Iranian cyber actors are deploying multi-stage malware that often masquerades as legitimate applications, including “Telegram_authenticator.exe” and “WhatsApp.exe.” Once a user downloads the malicious file, the software creates a “bot” that communicates directly with Telegram’s API.
This setup allows the Iranian government to:
-
Remotely Access Devices: Gain full control over infected Windows operating systems.
-
Exfiltrate Data: Steal sensitive documents, emails, and contact lists.
-
Track Opposition: Monitor the real-time communications and locations of activists and dissidents living both inside Iran and abroad.
“MOIS is using Telegram not just for communication, but as the primary infrastructure to push malware and carry out its geopolitical agenda,” the FBI report stated.
Seizures and Retaliation
The FBI’s warning follows a major law enforcement operation on Thursday, where the Department of Justice seized internet domains linked to Handala, a notorious pro-Iranian hacking group. Handala recently claimed responsibility for a destructive “wiper” attack against Stryker, a major U.S. medical technology firm, which the group described as retaliation for U.S. strikes that hit a girls’ school in Iran.
Despite the domain seizures, monitors report that Handala and other MOIS-linked groups have already migrated to new domains and continue to operate dozens of active Telegram channels to coordinate “DDoS” attacks and “hack-and-leak” operations.
The “Chaos Agent” Strategy
Cybersecurity experts note that while Iran may lack the raw resources of China or Russia, it has become a premier “chaos agent” in the digital realm. By using widely available platforms such as Telegram, Tehran can bypass traditional firewalls and reach targets directly through social engineering.
The FBI is urging all users, particularly those in the defense sector or involved in Iranian human rights advocacy, to exercise extreme caution when receiving unsolicited messages and to ensure all software is up to date with the latest security patches.
“As the kinetic war continues on the ground, the digital front is expanding into every smartphone and laptop,” said one senior cybersecurity analyst. “Telegram has become the new frontline.”