Signal
FBI and CISA warn of Iranian and Russian hacking campaigns targeting messaging app users
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-03-23 18:19 UTCUpdated 2026-03-24 13:39 UTC
rss
cveexploitsmalwarethreat_actorsincident_responsesecurity_policy
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
The FBI has alerted that Iranian government-linked hackers are deploying malware via Telegram to target dissidents, journalists, and opponents worldwide, using the app for stealthy command-and-control operations.
Entities
Stryker
Score total
1.15
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
- The FBI escalated alerts due to heightened geopolitical tensions involving Iran and U.S.-Israel alliances.
- Recent hack-and-leak campaigns by Iranian groups demonstrate evolving tactics and impact.
- Russian phishing campaigns are expanding globally, targeting high-value messaging accounts with sophisticated social engineering.
Why it matters
- Messaging apps are critical communication tools for dissidents, officials, and journalists worldwide.
- Hijacking accounts or deploying malware via these apps threatens privacy, security, and freedom of expression.
- Understanding these campaigns helps organizations and individuals strengthen defenses against state-backed cyber threats.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- Iranian government-linked hackers use Telegram to deploy malware targeting dissidents and opponents worldwide.
- Russian state-backed actors conduct phishing campaigns to hijack Signal and WhatsApp accounts globally.
How sources frame it
- FBI: neutral
- FBI And CISA: neutral
All evidence
All evidence
FBI, CISA warn of Russian hackers hijacking Signal and WhatsApp accounts
Malwarebytes Threat Analysis · malwarebytes.com · 2026-03-24 13:39 UTC
FBI: Iranian hackers targeting opponents with Telegram malware
CyberScoop · cyberscoop.com · 2026-03-23 18:35 UTC
Iran-backed Handala uses Telegram for C2 to push malware, FBI says
SC Media · scworld.com · 2026-03-23 18:19 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
- Malwarebytes Threat Analysis (1)
- CyberScoop (1)
- SC Media (1)
Top origin domains (this list)
- malwarebytes.com (1)
- cyberscoop.com (1)
- scworld.com (1)