
The FBI has alerted cybersecurity professionals about Iranian government-backed hackers using Telegram to conduct malware operations.
According to a warning released Friday, the FBI stated that Telegram serves as a command center for malware used to target journalists critical of Iran, Iranian dissidents, and other global opposition groups.
The FBI connected these attacks to Handala, an Iranian-linked hacktivist group supporting Palestinian causes, and Homeland Justice, an Iranian state-sponsored threat group linked to the Islamic Revolutionary Guard Corps (IRGC).
These Iranian hackers use social manipulation to infect victims’ devices with Windows malware, enabling them to steal screenshots and files.
“Given the tense geopolitical situation in the Middle East, the FBI is calling attention to this cyber activity by the MOIS,” the FBI stated.
“This malware led to intelligence gathering, data breaches, and harm to the reputation of targeted parties. The FBI is sharing this information to increase awareness of malicious Iranian cyber activity and offer methods to reduce the risk of being compromised.”
This warning came a day after the FBI seized four domain names (handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, and karmabelow80[.]org).
The Handala and Homeland Justice groups, as well as a third actor called Karma Below, used these websites for their attacks, where they leaked stolen sensitive data from victims based in the U.S. and worldwide.
These actions follow Handala’s cyberattack on Stryker, a U.S. medical technology company, where they remotely wiped around 80,000 company-managed devices using Microsoft Intune after compromising a Windows domain administrator account and creating a new Global Administrator account.
Last week, the FBI also warned about Russian intelligence operatives targeting Signal and WhatsApp users in phishing campaigns that have already compromised thousands of accounts.
“The activity targets individuals of high intelligence value, such as current and former U.S. government officials, military personnel, political figures, and journalists,” said the FBI in a public advisory after Dutch and French cybersecurity agencies reported similar account takeover attempts.
#fbi #hackers #handala #malware #news #spread #stay #telegram. #via #vigilant. — News
© Bulletproof Servers. All rights reserved.