• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Iran and Russia Weaponized Encrypted Messaging Apps, FBI Warns in Same-Day Alerts

  • SOFX Staff Writer
  • March 24, 2026
(David Trinks / Unsplash+)
Share on FacebookShare on TwitterLinkedIn

The FBI issued two separate cybersecurity advisories on March 20, attributing active campaigns by Iranian and Russian government-linked actors to the exploitation of commercial encrypted messaging platforms against journalists, dissidents, and current and former U.S. government personnel.

In flash advisory FLASH-20260320-001, the FBI attributed a Telegram-based malware operation to Iran’s Ministry of Intelligence and Security (MOIS), identifying the platform as live command-and-control (C2) infrastructure. The campaign, which the FBI said dates to at least 2023, targets Iranian dissidents, journalists opposed to the Iranian government, and other opposition groups worldwide.

Attackers first pose as known contacts or tech support to deliver malicious files disguised as common applications, including the AI video tool Pictory, the password manager KeePass, and Telegram itself. Once installed, the malware connects the infected device to a government-controlled Telegram bot at api.telegram.org, enabling remote screen and audio recording, file exfiltration, and cache captures.

The FBI assessed the disguise was customized per target, “which indicates the Iranian cyber actors likely performed target reconnaissance prior to engaging with the victim.”

The same day, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint public service announcement attributing a separate phishing campaign to Russian intelligence services.

The @FBI has identified cyber actors associated with Russian Intelligence Services targeting users of commercial messaging applications, including Signal.

The campaign targets individuals of high intelligence value, including current and former U.S. government officials,…

— FBI Director Kash Patel (@FBIDirectorKash) March 20, 2026


That operation has produced unauthorized access to thousands of accounts belonging to U.S. government officials, military personnel, political figures, and journalists across Signal, WhatsApp, and other commercial messaging applications. Attackers send messages crafted to resemble automated security notices, tricking users into linking attacker-controlled devices to their accounts.

The FBI and CISA stated the campaign exploits user behavior, not any vulnerability in the applications’ encryption.

Ensar Seker, chief information security officer at SOCRadar, a threat intelligence firm, said the Iran-linked operation reflects an accelerating pattern. “By leveraging a widely used application like Telegram, groups such as Handala significantly reduce the likelihood of detection, because security controls are often tuned to allow this traffic by default,” Seker said.

The FBI linked the Iran campaign to Handala Hack, the same MOIS-controlled group that claimed responsibility for a March cyberattack against medical technology company Stryker that wiped data from tens of thousands of employee devices.

The Justice Department announced last week that the court-authorized seizure of four domains tied to MOIS-controlled groups, two associated with Handala and two with a separate group called Homeland Justice.

In an 8-K filing with the U.S. Securities and Exchange Commission, Stryker said it was still recovering from the attack.

Telegram spokesperson Remi Vaughn said in an emailed statement that “moderators routinely remove any accounts found to be involved with malware.”

The advisories come as commercial messaging applications face broader scrutiny over government use. The Pentagon inspector general found in December 2025 that Defense Secretary Pete Hegseth used Signal to discuss a pending U.S. military strike on Houthi targets in Yemen, a finding the inspector general said violated department information-handling rules.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Ukraine’s AI-Powered ‘Terminator’ Drones Made First Killings Without Human Control

Ukraine’s AI-Powered ‘Terminator’ Drones Made First Killings Without Human Control

by SOFX Staff Writer
June 15, 2026
2

Fully autonomous drones operating without human oversight killed Russian soldiers during a battlefield test in Ukraine about two years ago,...

FBI Foils Drone-and-Sniper Plot on White House UFC Event

FBI Foils Drone-and-Sniper Plot on White House UFC Event

by SOFX Staff Writer
June 17, 2026
4

The FBI has arrested five people in connection with an alleged plot to attack President Donald Trump’s UFC Freedom 250...

Ukraine Wants Foreigners in Half Its Infantry, and Private Firms Will Deliver Them

Ukraine Wants Foreigners in Half Its Infantry, and Private Firms Will Deliver Them

by SOFX Staff Writer
June 12, 2026
2

Ukraine will let private companies recruit, screen, and deliver foreign fighters to its army, and it wants those foreigners to...

Pentagon Releases 162 Declassified UFO Files Spanning 1942 to 2025

Pentagon Releases 162 Declassified UFO Files Spanning 1942 to 2025

by SOFX Staff Writer
May 9, 2026
2

The Department of War published 162 declassified files on unidentified anomalous phenomena Friday, launching a dedicated government website and kicking...

ADVERTISEMENT
ADVERTISEMENT
Next Post
USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

USS Gerald R. Ford Arrives in Crete for Repairs, Leaving One U.S. Carrier in Iran Fight

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone’s Combat Record

Ukraine Downs Rare $400,000 Skat-450M Days After Russia Promoted the Drone's Combat Record

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz