• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Iran and Russia Weaponized Encrypted Messaging Apps, FBI Warns in Same-Day Alerts

  • SOFX Staff Writer
  • March 24, 2026
(David Trinks / Unsplash+)
Share on FacebookShare on TwitterLinkedIn

The FBI issued two separate cybersecurity advisories on March 20, attributing active campaigns by Iranian and Russian government-linked actors to the exploitation of commercial encrypted messaging platforms against journalists, dissidents, and current and former U.S. government personnel.

In flash advisory FLASH-20260320-001, the FBI attributed a Telegram-based malware operation to Iran’s Ministry of Intelligence and Security (MOIS), identifying the platform as live command-and-control (C2) infrastructure. The campaign, which the FBI said dates to at least 2023, targets Iranian dissidents, journalists opposed to the Iranian government, and other opposition groups worldwide.

Attackers first pose as known contacts or tech support to deliver malicious files disguised as common applications, including the AI video tool Pictory, the password manager KeePass, and Telegram itself. Once installed, the malware connects the infected device to a government-controlled Telegram bot at api.telegram.org, enabling remote screen and audio recording, file exfiltration, and cache captures.

The FBI assessed the disguise was customized per target, “which indicates the Iranian cyber actors likely performed target reconnaissance prior to engaging with the victim.”

The same day, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint public service announcement attributing a separate phishing campaign to Russian intelligence services.

The @FBI has identified cyber actors associated with Russian Intelligence Services targeting users of commercial messaging applications, including Signal.

The campaign targets individuals of high intelligence value, including current and former U.S. government officials,…

— FBI Director Kash Patel (@FBIDirectorKash) March 20, 2026


That operation has produced unauthorized access to thousands of accounts belonging to U.S. government officials, military personnel, political figures, and journalists across Signal, WhatsApp, and other commercial messaging applications. Attackers send messages crafted to resemble automated security notices, tricking users into linking attacker-controlled devices to their accounts.

The FBI and CISA stated the campaign exploits user behavior, not any vulnerability in the applications’ encryption.

Ensar Seker, chief information security officer at SOCRadar, a threat intelligence firm, said the Iran-linked operation reflects an accelerating pattern. “By leveraging a widely used application like Telegram, groups such as Handala significantly reduce the likelihood of detection, because security controls are often tuned to allow this traffic by default,” Seker said.

The FBI linked the Iran campaign to Handala Hack, the same MOIS-controlled group that claimed responsibility for a March cyberattack against medical technology company Stryker that wiped data from tens of thousands of employee devices.

The Justice Department announced last week that the court-authorized seizure of four domains tied to MOIS-controlled groups, two associated with Handala and two with a separate group called Homeland Justice.

In an 8-K filing with the U.S. Securities and Exchange Commission, Stryker said it was still recovering from the attack.

Telegram spokesperson Remi Vaughn said in an emailed statement that “moderators routinely remove any accounts found to be involved with malware.”

The advisories come as commercial messaging applications face broader scrutiny over government use. The Pentagon inspector general found in December 2025 that Defense Secretary Pete Hegseth used Signal to discuss a pending U.S. military strike on Houthi targets in Yemen, a finding the inspector general said violated department information-handling rules.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

The Bar Fight Is the PhD

The Bar Fight Is the PhD

by Dino Garner
May 22, 2026
4

Before I joined the 1st Ranger Battalion in 1994, I was a biophysicist. I had spent the better part of...

SOCOM Commander Says Special Operations Needs ‘PhDs Who Can Win a Bar Fight’

SOCOM Commander Says Special Operations Needs ‘PhDs Who Can Win a Bar Fight’

by SOFX Staff Writer
May 21, 2026
0

U.S. special operations forces need troops who are both combat-ready and technologically skilled as warfare becomes increasingly shaped by digital...

Air Force Tests Special Ops Plane Designed for Rapid Assembly in the Field

Air Force Tests Special Ops Plane Designed for Rapid Assembly in the Field

by SOFX Staff Writer
May 20, 2026
1

The U.S. Air Force Special Operations Command (AFSOC) is testing whether its new OA-1K Skyraider II aircraft can be rapidly...

AI Data Center Demand Drove 76 Percent Surge in Wholesale Power Prices Across East Cost Grid

AI Data Center Demand Drove 76 Percent Surge in Wholesale Power Prices Across East Cost Grid

by SOFX Staff Writer
May 15, 2026
1

Wholesale electricity prices across America's largest power grid jumped 76 percent in the first quarter of 2026, driven by surging...

ADVERTISEMENT
ADVERTISEMENT
Next Post
USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone’s Combat Record

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone's Combat Record

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz