FBI warns of Handala hackers using Telegram in malware attacks
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”这样的开头。首先,我需要仔细阅读文章,抓住主要信息。 文章主要讲的是FBI警告伊朗黑客利用Telegram进行网络攻击。这些黑客与伊朗情报部门有关,攻击目标包括批评伊朗政府的记者、伊朗异见人士以及全球的反对派团体。FBI提到他们使用了社交工程手段来传播恶意软件,导致数据泄露和声誉受损。此外,FBI还查封了几个被用来泄露敏感文件的域名。 接下来,我需要把这些信息浓缩到100字以内。重点包括:FBI警告、伊朗黑客、Telegram作为攻击工具、目标群体、数据泄露和声誉损害,以及查封域名。 最后,确保语言简洁明了,直接描述内容,不使用任何开头语。 </think> 美国联邦调查局警告称,伊朗黑客利用Telegram进行网络攻击,目标包括批评伊朗政府的记者、异见人士及全球反对派团体。这些攻击导致数据泄露和声誉受损。FBI还查封了多个用于泄露敏感文件的域名。 2026-3-23 10:0:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:7 收藏

Iran Telegram flag

The U.S. Federal Bureau of Investigation (FBI) warned network defenders that Iranian hackers linked to the country's Ministry of Intelligence and Security (MOIS) are using Telegram in malware attacks.

In a flash alert issued on Friday, the FBI says Telegram is being used as command-and-control (C2) infrastructure by malware targeting journalists criticizing the Iranian government, Iranian dissidents, and various other oppositional groups worldwide.

The bureau linked these attacks to the Iranian-linked and pro-Palestinian Handala hacktivist group (also known as Handala Hack Team, Hatef, Hamsa) and the Iranian state-sponsored Homeland Justice threat group tied to Iran's Islamic Revolutionary Guard Corps (IRGC).

In these attacks, the Iranian hackers are using social engineering to infect targets' devices with Windows malware that enables them to exfiltrate screenshots or files from compromised computers.

"Due to the elevated geopolitical climate of the Middle East and current conflict, the FBI is highlighting this MOIS cyber activity," the bureau said.

"This malware resulted in intelligence collection, data leaks, and reputational harm against the targeted parties. The FBI is releasing this information to maximize awareness of malicious Iranian cyber activity and provide mitigation strategies to reduce the risk of compromise."

Iranian malware attacks abusing Telegram
Iranian malware attacks abusing Telegram (FBI)

This warning was published one day after the FBI seized four domains (handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, and karmabelow80[.]org).

The websites available via the seized clearnet domains were used by the Handala and Homeland Justice threat groups, and a third threat actor tracked as Karma Below, during their attacks and to leak sensitive documents and data stolen in cyberattacks targeting victims in the United States and around the world.

These actions follow Handala's cyberattack on U.S. medical giant Stryker, in which they factory reset approximately 80,000 devices (including employees' personal computers and mobile devices managed by the company) using the Microsoft Intune wipe command after compromising a Windows domain administrator account and creating a new Global Administrator account.

Last week, the FBI also warned that Russian intelligence-linked threat actors are targeting Signal and WhatsApp users in phishing campaigns that have already compromised thousands of accounts.

"The activity targets individuals of high intelligence value, such as current and former U.S. government officials, military personnel, political figures, and journalists," said the FBI  in a public service announcement issued after Dutch and French cybersecurity authorities described similar account-hijacking operations.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/fbi-warns-of-handala-hackers-using-telegram-in-malware-attacks/
如有侵权请联系:admin#unsafe.sh