HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Iranian Handala Hacktivist Group Exploits Telegram for Malware C2, Targeting Journalists and Dissidents

The FBI warned that the Iran‑linked Handala group is using Telegram as a command‑and‑control platform for Windows malware aimed at journalists, human‑rights activists and other high‑value targets. The campaign includes credential‑theft, screenshot exfiltration and remote device wipes via compromised Microsoft Intune accounts, raising significant third‑party risk for organizations that rely on these services.

LiveThreat™ Intelligence · 📅 March 23, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Iranian Handala Hacktivist Group Leveraging Telegram for Malware C2 Targeting Journalists, Dissidents and High‑Value Individuals

What Happened – The FBI disclosed that the Iran‑linked Handala hacktivist team is using Telegram as a command‑and‑control (C2) channel for Windows‑based malware. The malware is delivered via social‑engineering lures and is designed to capture screenshots, steal files, and in some cases, issue remote wipe commands through compromised Microsoft Intune accounts (as seen in the Stryker incident).

Why It Matters for TPRM

  • Telegram‑based C2 is difficult to detect with traditional network proxies, increasing the risk of silent data exfiltration.
  • The threat actors target journalists, NGOs, and government‑affiliated individuals, exposing third‑party vendors that support these entities to reputational and intelligence‑leak risks.
  • Use of legitimate cloud services (Telegram, Microsoft Intune) blurs the line between benign and malicious traffic, demanding tighter third‑party monitoring.

Who Is Affected – Media & journalism firms, human‑rights NGOs, government agencies, healthcare providers (e.g., Stryker), and any organization that relies on Microsoft Intune or similar endpoint‑management solutions.

Recommended Actions

  • Block or closely monitor Telegram traffic from corporate endpoints and enforce strict egress filtering.
  • Deploy endpoint detection and response (EDR) rules that flag suspicious PowerShell or credential‑dumping activity linked to known Handala IOCs.
  • Verify that privileged accounts (especially Global Administrators in Azure AD/Intune) have MFA and least‑privilege access.
  • Review contracts with third‑party communications and endpoint‑management providers for security‑by‑design clauses.

Technical Notes – Attack vector: phishing/social engineering → Windows malware → Telegram C2. The group has also leveraged compromised Azure AD/Intune credentials to issue remote wipe commands, demonstrating a hybrid credential‑compromise and malware strategy. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/fbi-warns-of-handala-hackers-using-telegram-in-malware-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →