- Updated: March 23, 2026
- 6 min read
FBI Warns: Iranian Hackers Exploit Telegram for Malware Attacks
Iranian state‑backed hackers are exploiting Telegram to deliver malware and conduct espionage, according to a newly released FBI alert.
FBI Warns: Iranian Hackers Use Telegram for Sophisticated Malware Campaigns
Figure 1 – FBI’s latest threat‑intel briefing on Telegram‑based malware attacks.
Why this matters now
The cyber‑threat landscape has shifted dramatically in 2026, with messaging platforms becoming the new front‑line for covert operations. The FBI’s recent alert reveals that Iranian actors are weaponising Telegram—one of the world’s most popular encrypted messengers—to infiltrate the devices of dissidents, journalists, and opposition groups worldwide. This tactic not only bypasses traditional network defenses but also blends malicious traffic with legitimate user conversations, making detection exceptionally challenging.
Key findings from the FBI investigation
- At least 27 distinct malware families were linked to Telegram‑based delivery vectors.
- Attackers impersonate trusted contacts or “tech‑support” agents to persuade victims into clicking malicious links.
- Once installed, the payload establishes a persistent connection to Telegram bots that act as remote‑control C2 (command‑and‑control) servers.
- Victims reported stolen files, screen captures, and intercepted Zoom calls within 48 hours of infection.
- The operations are attributed to Iran’s Ministry of Intelligence and Security (MOIS), aligning with Tehran’s broader geopolitical agenda.
Mechanics of the Telegram‑malware pipeline
Understanding the attack chain helps defenders disrupt it at the earliest stage. The FBI outlines a two‑phase process:
Phase 1 – Social engineering & payload drop
Attackers initiate contact via Telegram, often masquerading as a known colleague, a humanitarian aid worker, or a “support” representative. They send a short message containing a link that appears to lead to a legitimate app update (e.g., “Telegram v8.5 Update”) or a popular file‑sharing service. The link actually points to a malicious executable or a disguised script that, once run, installs a hidden backdoor.
Phase 2 – Bot‑mediated command and control
After the backdoor is in place, the compromised host automatically joins a pre‑configured Telegram bot channel. These bots relay commands from the attacker’s control panel, allowing real‑time actions such as:
- File exfiltration (documents, credentials, encrypted archives).
- Screen capture and webcam snapshots.
- Audio recording of VoIP calls, including Zoom and Microsoft Teams.
- Execution of arbitrary shell commands for lateral movement.
Because Telegram traffic is encrypted and widely trusted, many network security tools struggle to differentiate malicious bot traffic from ordinary user chats.
Who is being targeted?
The FBI’s intelligence points to three primary victim categories:
- Dissidents and human‑rights activists – Individuals who publicly oppose the Iranian regime, often operating from exile.
- Journalists and media organisations – Reporters covering Middle‑East politics, especially those publishing investigative pieces on Iran.
- Opposition political groups – NGOs and think‑tanks that facilitate policy analysis or advocacy against Tehran’s policies.
These groups are attractive to MOIS because compromising their communications yields both strategic intelligence and the ability to sow disinformation.
Broader implications for the cybersecurity community
Telegram’s rise as a C2 channel forces a reassessment of traditional detection models. Security teams must now consider:
- Encrypted traffic visibility – Deploy SSL/TLS interception proxies or use endpoint‑based telemetry to surface anomalous bot‑related API calls.
- User‑education refreshers – Reinforce phishing awareness that specifically mentions “messenger‑based” lures.
- Zero‑trust network segmentation – Isolate high‑risk user groups (e.g., journalists) from critical assets.
- Threat‑intel sharing – Contribute IoCs (Indicators of Compromise) to platforms like MISP to accelerate community response.
“The use of Telegram as a covert command‑and‑control channel enables Iranian actors to blend malicious traffic with legitimate user communications, dramatically reducing the odds of detection by conventional security solutions,” the FBI stated in its public alert.
Actionable security recommendations
Organizations can adopt a layered defense strategy to mitigate the Telegram‑based threat:
1. Harden endpoint security
- Deploy next‑generation anti‑malware that inspects executable signatures before launch.
- Enable application whitelisting for critical workstations.
2. Strengthen email and messenger hygiene
- Block unknown or suspicious Telegram links via web‑filtering solutions.
- Educate users to verify unexpected file‑share requests through a secondary channel.
3. Deploy network‑level anomaly detection
- Monitor outbound connections to Telegram’s API endpoints (e.g.,
api.telegram.org). - Set alerts for abnormal data‑exfiltration volumes from user devices.
4. Leverage AI‑driven threat hunting
Modern AI platforms can correlate seemingly benign Telegram traffic with endpoint behaviours, surfacing hidden C2 patterns. For example, UBOS’s AI marketing agents and Workflow automation studio can be repurposed to flag suspicious bot interactions in real time.
For a full journalistic account, see the original TechCrunch coverage:
TechCrunch – FBI report on Iranian hackers using Telegram.
Explore UBOS solutions that help defend against messenger‑based threats
UBOS offers a suite of AI‑enhanced tools that can be integrated directly into your security stack:
- Telegram integration on UBOS – Seamlessly ingest Telegram logs for automated threat analysis.
- ChatGPT and Telegram integration – Leverage large‑language‑model insights to triage suspicious messages.
- OpenAI ChatGPT integration – Generate real‑time incident response playbooks.
- Chroma DB integration – Store vector embeddings of malicious payloads for fast similarity search.
- ElevenLabs AI voice integration – Convert alert summaries into audible briefings for SOC analysts on the go.
- UBOS platform overview – A unified AI‑first environment for threat detection, response, and automation.
- Enterprise AI platform by UBOS – Scalable across global operations, ideal for large‑scale SOCs.
- Web app editor on UBOS – Build custom dashboards to visualise Telegram‑related alerts.
- UBOS templates for quick start – Deploy pre‑built “Malware‑C2 Detection” templates in minutes.
- UBOS partner program – Collaborate with UBOS to co‑develop bespoke threat‑intel solutions.
Relevant UBOS Template Marketplace assets
These ready‑made templates can accelerate your response to Telegram‑based attacks:
- GPT‑Powered Telegram Bot – Simulate benign bot traffic for baseline profiling.
- AI Article Copywriter – Automate threat‑intel report generation.
- AI Survey Generator – Collect post‑incident feedback from affected users.
- AI YouTube Comment Analysis tool – Detect disinformation campaigns that often accompany state‑sponsored attacks.
- AI SEO Analyzer – Ensure your public advisories rank high for “Telegram malware” queries.
Conclusion
The FBI’s alert underscores a critical evolution in cyber‑espionage: leveraging popular, encrypted messaging apps to hide malicious command‑and‑control traffic. Organizations that rely on Telegram for legitimate collaboration must now treat the platform as a potential attack surface. By combining robust endpoint controls, network‑level monitoring, and AI‑driven analytics—such as those offered by UBOS—security teams can detect and disrupt these covert campaigns before sensitive data is exfiltrated.
Stay vigilant, keep your security stack intelligent, and remember: the line between a harmless chat and a hostile intrusion is often just one malicious link away.
Andrii Bidochko
CTO UBOS
Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.