Targeted campaign uses Telegram to control malware
An FBI report describes a campaign attributed to Iran's Ministry of Intelligence in which attackers use social engineering via messaging platforms to trick targets into opening malicious files. The malware establishes command-and-control via Telegram, maintains persistence, and supports surveillance, data collection and credential theft. The campaign primarily targets dissidents, journalists and others perceived as opposing the Iranian government.
What this means for your organisation
Using Telegram as a control channel means the traffic blends into ordinary use and is hard to separate out with traditional network monitoring. Although the targets are individuals, the technique reaches organisations when such people are employees, partners or sources, and when personal devices are used for work. State-linked campaigns also show a persistence that makes one rejected attempt rarely the last.
Berigo recommends
- Separate work data from personal devices for staff in exposed roles.
- Restrict and log the use of messaging apps on corporate devices.
- Provide targeted training to employees who may be of interest to state actors.
- Establish a low-threshold channel for reporting suspicious files and approaches.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch