Iranian Telegram-Controlled Surveillance Malware (State-Sponsored Spyware Campaign)
First seen Sep 16, 2026 · Updated Sep 16, 2026
US, UK, and Dutch cybersecurity agencies have jointly disclosed a Windows-based spyware toolset used by an Iranian intelligence-linked threat actor to surveil dissidents, journalists, and activists globally. The malware uses Telegram as its command-and-control channel and is capable of exfiltrating emails, chat logs, screenshots, and live microphone audio.
Technical Analysis
The malware operates as a Windows implant that leverages the Telegram Bot API for command-and-control, allowing operators to blend malicious traffic with legitimate messaging service traffic and evade traditional network-based detection and domain blocklisting. Capabilities include harvesting of email and chat application data, periodic screenshot capture, and remote activation of the host microphone for audio surveillance, indicating a modular architecture designed for long-term covert monitoring rather than destructive impact. Initial access is likely achieved via targeted phishing or social engineering against high-risk individuals, consistent with known Iranian state-sponsored tradecraft (e.g., groups tracked as APT35/Charming Kitten). No specific CVEs have been disclosed in connection with this campaign, suggesting reliance on social engineering and legitimate-looking payloads rather than exploitation of unpatched vulnerabilities. If deployed on endpoints used to operate AI agent tooling or LLM-integrated applications, the malware's ability to harvest chat logs, clipboard data, and screenshots could expose API keys, credentials, and sensitive prompts/outputs handled by local agent clients, warranting inclusion under agent-relevant credential exposure risks.
Affected Systems
Microsoft Windows desktop/laptop systems used by journalists, activists, dissidents, and civil society organizations; any Windows host running Telegram or messaging clients alongside sensitive communications or credential stores
Indicators of Compromise
- No specific hashes, IPs, or domains provided in source reporting; refer to joint CISA/NCSC/NCSC-NL advisory for full IOC list
Remediation Steps
- 1
Monitor Telegram API Traffic
Inspect and restrict outbound connections to Telegram Bot API endpoints from corporate or high-risk endpoints where such traffic is not business-justified.
- 2
Endpoint Detection and Response
Deploy EDR solutions capable of detecting anomalous microphone activation, screenshot capture utilities, and unauthorized access to email/chat client data stores.
- 3
User Awareness Training
Provide targeted phishing and social engineering awareness training for high-risk populations such as journalists, activists, and NGO staff.
- 4
Credential and API Key Rotation
For organizations running AI agent tooling on potentially exposed endpoints, rotate API keys and credentials, and audit for unauthorized access following any suspected compromise.
- 5
Apply Joint Advisory Guidance
Review and implement mitigations from the joint US/UK/Netherlands cybersecurity advisory, including indicators of compromise and detection signatures once published.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.