• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Iran and Russia Weaponized Encrypted Messaging Apps, FBI Warns in Same-Day Alerts

  • SOFX Staff Writer
  • March 24, 2026
(David Trinks / Unsplash+)
Share on FacebookShare on TwitterLinkedIn

The FBI issued two separate cybersecurity advisories on March 20, attributing active campaigns by Iranian and Russian government-linked actors to the exploitation of commercial encrypted messaging platforms against journalists, dissidents, and current and former U.S. government personnel.

In flash advisory FLASH-20260320-001, the FBI attributed a Telegram-based malware operation to Iran’s Ministry of Intelligence and Security (MOIS), identifying the platform as live command-and-control (C2) infrastructure. The campaign, which the FBI said dates to at least 2023, targets Iranian dissidents, journalists opposed to the Iranian government, and other opposition groups worldwide.

Attackers first pose as known contacts or tech support to deliver malicious files disguised as common applications, including the AI video tool Pictory, the password manager KeePass, and Telegram itself. Once installed, the malware connects the infected device to a government-controlled Telegram bot at api.telegram.org, enabling remote screen and audio recording, file exfiltration, and cache captures.

The FBI assessed the disguise was customized per target, “which indicates the Iranian cyber actors likely performed target reconnaissance prior to engaging with the victim.”

The same day, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint public service announcement attributing a separate phishing campaign to Russian intelligence services.

The @FBI has identified cyber actors associated with Russian Intelligence Services targeting users of commercial messaging applications, including Signal.

The campaign targets individuals of high intelligence value, including current and former U.S. government officials,…

— FBI Director Kash Patel (@FBIDirectorKash) March 20, 2026


That operation has produced unauthorized access to thousands of accounts belonging to U.S. government officials, military personnel, political figures, and journalists across Signal, WhatsApp, and other commercial messaging applications. Attackers send messages crafted to resemble automated security notices, tricking users into linking attacker-controlled devices to their accounts.

The FBI and CISA stated the campaign exploits user behavior, not any vulnerability in the applications’ encryption.

Ensar Seker, chief information security officer at SOCRadar, a threat intelligence firm, said the Iran-linked operation reflects an accelerating pattern. “By leveraging a widely used application like Telegram, groups such as Handala significantly reduce the likelihood of detection, because security controls are often tuned to allow this traffic by default,” Seker said.

The FBI linked the Iran campaign to Handala Hack, the same MOIS-controlled group that claimed responsibility for a March cyberattack against medical technology company Stryker that wiped data from tens of thousands of employee devices.

The Justice Department announced last week that the court-authorized seizure of four domains tied to MOIS-controlled groups, two associated with Handala and two with a separate group called Homeland Justice.

In an 8-K filing with the U.S. Securities and Exchange Commission, Stryker said it was still recovering from the attack.

Telegram spokesperson Remi Vaughn said in an emailed statement that “moderators routinely remove any accounts found to be involved with malware.”

The advisories come as commercial messaging applications face broader scrutiny over government use. The Pentagon inspector general found in December 2025 that Defense Secretary Pete Hegseth used Signal to discuss a pending U.S. military strike on Houthi targets in Yemen, a finding the inspector general said violated department information-handling rules.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Marine Lance Corporal 3D-Prints $10 Fix for a $5,600 Antenna Mast

Marine Lance Corporal 3D-Prints $10 Fix for a $5,600 Antenna Mast

by SOFX Staff Writer
March 23, 2026
6

A U.S. Marine has developed a 3D-printed replacement for a commonly broken antenna mast used in a key military communications...

Eight of Ten AI Chatbots Assisted Teen Users Planning Violent Attacks, Joint Investigation Finds

U.S. Drops New 5,000-lb Bunker Busters on Iranian Anti-Ship Missile Sites Near Hormuz

by SOFX Staff Writer
March 19, 2026
0

U.S. forces struck Iranian anti-ship missile sites near the Strait of Hormuz on Tuesday using 5,000-pound bunker-buster bombs, U.S. Central...

Open-Source $96 MANPADS Prototype Published to GitHub, Raising Security Concerns

Open-Source $96 MANPADS Prototype Published to GitHub, Raising Security Concerns

by SOFX Staff Writer
March 17, 2026
3

Independent engineer Alisher Khojayev published a man-portable air-defense system (MANPADS) prototype to GitHub on March 11, 2026, drawing scrutiny from...

ADVERTISEMENT
ADVERTISEMENT
Next Post
USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone’s Combat Record

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone's Combat Record

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz