Cybersecurity authorities in the United States, the United Kingdom, and the Netherlands have identified a Windows malware that they claim Iran's intelligence service uses to surveil dissidents, journalists, and activists worldwide This article explores malware claim iran. . The malware is remotely controlled via the Telegram messaging app and can capture emails, chat messages, screenshots, and activate microphones to record audio.
The NCSC, FBI, and the Netherlands' AIVD jointly released a joint advisory on September 15. The attackers impersonate someone the target knows or as tech support for a messaging app, gradually building trust before sending a file that appears to be a legitimate program, according to the agencies. Reports indicate disguises involving the AI video app Pictory, password manager KeePass, Telegram, RunwayML, Norton Antivirus, and Adobe Flash Player.
Once active, the malware can perform various actions: listing running applications, taking screenshots, enabling the microphone, copying data from the Telegram and WhatsApp browsers, stealing passwords and email addresses, downloading additional malware, and deleting files. To minimize the risk, the agencies recommend the following actions: Do not open files sent via messages or links, and download software exclusively from official websites or app stores. When the FBI initially warned about the campaign in March, Telegram's moderators "regularly removed any accounts found to be involved with malware."
Agencies present their conclusions as assessments rather than as settled court matters.











