highAPT

Iranian Telegram-Controlled Surveillance Malware (State-Sponsored Spyware Campaign)

First seen Sep 16, 2026 · Updated Sep 16, 2026

iranaptsurveillancetelegram-c2espionagejournalistscivil-societystate-sponsored

US, UK, and Dutch cybersecurity agencies have jointly disclosed a Windows-based spyware toolset used by an Iranian intelligence-linked threat actor to surveil dissidents, journalists, and activists globally. The malware uses Telegram as its command-and-control channel and is capable of exfiltrating emails, chat logs, screenshots, and live microphone audio.

Technical Analysis

The malware operates as a Windows implant that leverages the Telegram Bot API for command-and-control, allowing operators to blend malicious traffic with legitimate messaging service traffic and evade traditional network-based detection and domain blocklisting. Capabilities include harvesting of email and chat application data, periodic screenshot capture, and remote activation of the host microphone for audio surveillance, indicating a modular architecture designed for long-term covert monitoring rather than destructive impact. Initial access is likely achieved via targeted phishing or social engineering against high-risk individuals, consistent with known Iranian state-sponsored tradecraft (e.g., groups tracked as APT35/Charming Kitten). No specific CVEs have been disclosed in connection with this campaign, suggesting reliance on social engineering and legitimate-looking payloads rather than exploitation of unpatched vulnerabilities. If deployed on endpoints used to operate AI agent tooling or LLM-integrated applications, the malware's ability to harvest chat logs, clipboard data, and screenshots could expose API keys, credentials, and sensitive prompts/outputs handled by local agent clients, warranting inclusion under agent-relevant credential exposure risks.

Affected Systems

Microsoft Windows desktop/laptop systems used by journalists, activists, dissidents, and civil society organizations; any Windows host running Telegram or messaging clients alongside sensitive communications or credential stores

Indicators of Compromise

  • No specific hashes, IPs, or domains provided in source reporting; refer to joint CISA/NCSC/NCSC-NL advisory for full IOC list

Remediation Steps

  1. 1

    Monitor Telegram API Traffic

    Inspect and restrict outbound connections to Telegram Bot API endpoints from corporate or high-risk endpoints where such traffic is not business-justified.

  2. 2

    Endpoint Detection and Response

    Deploy EDR solutions capable of detecting anomalous microphone activation, screenshot capture utilities, and unauthorized access to email/chat client data stores.

  3. 3

    User Awareness Training

    Provide targeted phishing and social engineering awareness training for high-risk populations such as journalists, activists, and NGO staff.

  4. 4

    Credential and API Key Rotation

    For organizations running AI agent tooling on potentially exposed endpoints, rotate API keys and credentials, and audit for unauthorized access following any suspected compromise.

  5. 5

    Apply Joint Advisory Guidance

    Review and implement mitigations from the joint US/UK/Netherlands cybersecurity advisory, including indicators of compromise and detection signatures once published.

Industries Most Exposed

mediahuman-rights-organizationsngogovernmentcivil-society

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.