Iran's Spy Malware Runs on Telegram, Western Agencies Warn

US, UK and Dutch cyber agencies say Iranian intelligence uses a Windows tool controlled through Telegram to watch dissidents and activists abroad.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Aerial view, 16:9 framing, photoreal editorial style, a dense suburban neighbourhood at dusk with hundreds of softly glowing house windows, each window subtly e
Share

Key points

  • Cybersecurity agencies from the US, UK and the Netherlands have jointly attributed a Windows spying tool to Iran's intelligence service.
  • The malware is operated through the Telegram messaging app rather than a dedicated server.
  • Targets include dissidents and human rights activists living outside Iran.
  • Once installed, the tool can steal emails and chat messages, take screenshots, and switch on the microphone to record audio.
  • The joint advisory is a public attribution, not a report of a fresh breach.

Three Western governments have put their names to the same finger-pointing exercise, and that's the part worth watching. Attribution advisories don't appear often, and when they do the goal is usually to burn a tool the spies were still using.

The agencies say Iran's intelligence service is behind a piece of Windows malware built for surveillance rather than theft. It sits quietly on a target's computer and hands control to an operator on the other end of a Telegram chat. Telegram is a mainstream messaging app used by hundreds of millions of people. Here it doubles as the remote control: instead of the malware phoning home to a suspicious server, it takes its orders through ordinary-looking Telegram traffic, which is harder for a company network to spot.

Who is being targeted?

The advisory names dissidents and activists as the intended victims. These are people Tehran has long tried to monitor abroad, not the kind of corporate or government networks most defenders are watching.

That focus matters. Spyware aimed at individuals tends to arrive through a personal email, a fake job offer, or a document sent by someone the target already trusts. It's a people problem before it's a technology problem.

The advisory does not put a number on how many people have been infected.

What can the malware actually do?

Once it's running on a Windows PC, the tool can read a victim's emails and chat messages, capture what is on the screen, and turn on the built-in microphone to record whatever is being said in the room.

An operator sitting in front of a Telegram window can watch a journalist type, read the replies from a source, and listen to the conversation happening next to the laptop. No separate app the victim would notice ever opens. Screenshots and audio go back out through the same Telegram channel, mixed in with the ordinary traffic of a widely used app.

We reported on 26 August that Iran's Nimbus Manticore group quietly built out fresh custom malware and infrastructure in 2026; this advisory shows a parallel Iranian capability aimed squarely at individuals rather than networks.

Should you worry?

Most readers aren't the target here. Campaigners, exiled reporters and opposition figures should assume their personal devices are of interest and treat unexpected attachments with suspicion, even when they appear to come from a known contact.

Basic steps still help. Keep Windows and antivirus up to date. Don't install software sent over chat. If a device starts behaving oddly, the microphone light flickering on or the fan running when nothing is open, take it to a specialist rather than trying to clean it yourself.

Journalist safety groups and organisations such as Access Now run free help lines for people who think they've been targeted by a state.

How this fits the wider pattern

Iran joins a short list of countries with a named, exposed spying toolkit aimed at its own diaspora. Hiding command traffic inside a legitimate consumer app isn't new, but it keeps working because network defenders are reluctant to block Telegram outright.

Public advisories usually shorten a campaign's life. They rarely end it. Expect the operators to retool.

© 2026 Threat Vectr