✨ From vibe coding to vibe deployment. UBOS MCP turns ideas into infra with one message.

Learn more
Andrii Bidochko
  • Updated: March 23, 2026
  • 6 min read

FBI Warns: Iranian Hackers Exploit Telegram for Malware Attacks

Iranian state‑backed hackers are exploiting Telegram to deliver malware and conduct espionage, according to a newly released FBI alert.

FBI Warns: Iranian Hackers Use Telegram for Sophisticated Malware Campaigns

FBI report on Iranian hackers using Telegram

Figure 1 – FBI’s latest threat‑intel briefing on Telegram‑based malware attacks.

Why this matters now

The cyber‑threat landscape has shifted dramatically in 2026, with messaging platforms becoming the new front‑line for covert operations. The FBI’s recent alert reveals that Iranian actors are weaponising Telegram—one of the world’s most popular encrypted messengers—to infiltrate the devices of dissidents, journalists, and opposition groups worldwide. This tactic not only bypasses traditional network defenses but also blends malicious traffic with legitimate user conversations, making detection exceptionally challenging.

Key findings from the FBI investigation

  • At least 27 distinct malware families were linked to Telegram‑based delivery vectors.
  • Attackers impersonate trusted contacts or “tech‑support” agents to persuade victims into clicking malicious links.
  • Once installed, the payload establishes a persistent connection to Telegram bots that act as remote‑control C2 (command‑and‑control) servers.
  • Victims reported stolen files, screen captures, and intercepted Zoom calls within 48 hours of infection.
  • The operations are attributed to Iran’s Ministry of Intelligence and Security (MOIS), aligning with Tehran’s broader geopolitical agenda.

Mechanics of the Telegram‑malware pipeline

Understanding the attack chain helps defenders disrupt it at the earliest stage. The FBI outlines a two‑phase process:

Phase 1 – Social engineering & payload drop

Attackers initiate contact via Telegram, often masquerading as a known colleague, a humanitarian aid worker, or a “support” representative. They send a short message containing a link that appears to lead to a legitimate app update (e.g., “Telegram v8.5 Update”) or a popular file‑sharing service. The link actually points to a malicious executable or a disguised script that, once run, installs a hidden backdoor.

Phase 2 – Bot‑mediated command and control

After the backdoor is in place, the compromised host automatically joins a pre‑configured Telegram bot channel. These bots relay commands from the attacker’s control panel, allowing real‑time actions such as:

  • File exfiltration (documents, credentials, encrypted archives).
  • Screen capture and webcam snapshots.
  • Audio recording of VoIP calls, including Zoom and Microsoft Teams.
  • Execution of arbitrary shell commands for lateral movement.

Because Telegram traffic is encrypted and widely trusted, many network security tools struggle to differentiate malicious bot traffic from ordinary user chats.

Who is being targeted?

The FBI’s intelligence points to three primary victim categories:

  1. Dissidents and human‑rights activists – Individuals who publicly oppose the Iranian regime, often operating from exile.
  2. Journalists and media organisations – Reporters covering Middle‑East politics, especially those publishing investigative pieces on Iran.
  3. Opposition political groups – NGOs and think‑tanks that facilitate policy analysis or advocacy against Tehran’s policies.

These groups are attractive to MOIS because compromising their communications yields both strategic intelligence and the ability to sow disinformation.

Broader implications for the cybersecurity community

Telegram’s rise as a C2 channel forces a reassessment of traditional detection models. Security teams must now consider:

  • Encrypted traffic visibility – Deploy SSL/TLS interception proxies or use endpoint‑based telemetry to surface anomalous bot‑related API calls.
  • User‑education refreshers – Reinforce phishing awareness that specifically mentions “messenger‑based” lures.
  • Zero‑trust network segmentation – Isolate high‑risk user groups (e.g., journalists) from critical assets.
  • Threat‑intel sharing – Contribute IoCs (Indicators of Compromise) to platforms like MISP to accelerate community response.

“The use of Telegram as a covert command‑and‑control channel enables Iranian actors to blend malicious traffic with legitimate user communications, dramatically reducing the odds of detection by conventional security solutions,” the FBI stated in its public alert.

Actionable security recommendations

Organizations can adopt a layered defense strategy to mitigate the Telegram‑based threat:

1. Harden endpoint security

  • Deploy next‑generation anti‑malware that inspects executable signatures before launch.
  • Enable application whitelisting for critical workstations.

2. Strengthen email and messenger hygiene

  • Block unknown or suspicious Telegram links via web‑filtering solutions.
  • Educate users to verify unexpected file‑share requests through a secondary channel.

3. Deploy network‑level anomaly detection

  • Monitor outbound connections to Telegram’s API endpoints (e.g., api.telegram.org).
  • Set alerts for abnormal data‑exfiltration volumes from user devices.

4. Leverage AI‑driven threat hunting

Modern AI platforms can correlate seemingly benign Telegram traffic with endpoint behaviours, surfacing hidden C2 patterns. For example, UBOS’s AI marketing agents and Workflow automation studio can be repurposed to flag suspicious bot interactions in real time.

For a full journalistic account, see the original TechCrunch coverage:
TechCrunch – FBI report on Iranian hackers using Telegram.

Explore UBOS solutions that help defend against messenger‑based threats

UBOS offers a suite of AI‑enhanced tools that can be integrated directly into your security stack:

Relevant UBOS Template Marketplace assets

These ready‑made templates can accelerate your response to Telegram‑based attacks:

Conclusion

The FBI’s alert underscores a critical evolution in cyber‑espionage: leveraging popular, encrypted messaging apps to hide malicious command‑and‑control traffic. Organizations that rely on Telegram for legitimate collaboration must now treat the platform as a potential attack surface. By combining robust endpoint controls, network‑level monitoring, and AI‑driven analytics—such as those offered by UBOS—security teams can detect and disrupt these covert campaigns before sensitive data is exfiltrated.

Stay vigilant, keep your security stack intelligent, and remember: the line between a harmless chat and a hostile intrusion is often just one malicious link away.


Andrii Bidochko

CTO UBOS

Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.

Sign up for our newsletter

Stay up to date with the roadmap progress, announcements and exclusive discounts feel free to sign up with your email.

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.