The FBI Cyber Division has issued a critical advisory revealing that Iranian cyber actors are using Telegram as command-and-control (C2) infrastructure to deploy malware targeting Iranian dissidents and opposition groups worldwide. The operation, detailed in FBI FLASH Number FLASH-20260320-001, has resulted in significant data leaks and reputational harm to individuals and organizations opposing the Iranian regime.
This sophisticated campaign marks a concerning evolution in state-sponsored cyber tactics. By exploiting Telegram—a popular encrypted messaging platform—Iranian actors can discreetly issue commands to infected devices, exfiltrate sensitive data, and maintain persistent access to targets. The victims, primarily Iranian dissidents and opposition figures living outside Iran, face not only digital compromise but also physical danger as leaked information can expose their identities and networks to retaliation.
The FBI's advisory urges heightened vigilance, recommending that at-risk individuals implement robust security measures, including multi-factor authentication, endpoint detection tools, and caution when engaging with unsolicited messages on any platform—even encrypted ones. This threat arrives as the CFTC also highlights its oversight role in protecting critical sectors, underscoring the broader need for vigilant regulatory and security frameworks across both traditional and digital domains.
As state-sponsored cyber operations grow more sophisticated, this latest alert serves as a stark reminder: digital platforms designed for connection can be weaponized, and protecting vulnerable populations requires constant adaptation from security agencies and individuals alike.
Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.




