FBI Alert: Iranian MOIS Hackers Weaponize Telegram as C2 Channel to Target Dissidents Worldwide

The FBI has issued a critical alert warning that Iranian government hackers are weaponizing Telegram as a command and control (C2) channel to steal data from dissidents, opposition groups, and journalists who oppose the regime around the world. According to the FBI alert published Friday, hackers working for Iran’s Ministry of Intelligence and Security (MOIS)…

Read More

FBI Confirms Handala Hackers Breached Director Patel’s Personal Email Account

Iran-linked hackers have successfully breached the personal email account of FBI Director Kash Patel, publishing photos, documents, and email correspondence in a significant escalation of cyber operations targeting senior U.S. government officials. The Handala Hack Team, a hacktivist persona operating on behalf of Iran’s Ministry of Intelligence and Security (MOIS), announced the compromise on Friday,…

Read More

Iranian Handala Hackers Breach FBI Director Kash Patel’s Personal Email, Leak Photos and Documents

Iran-linked hacking group Handala Hack Team has successfully breached the personal email account of FBI Director Kash Patel, publishing photographs and documents stolen from his inbox, according to The Guardian and confirmed by the FBI. Attack Details The breach was announced by Handala on their website, where they stated that Patel “will now find his…

Read More

FBI Alert: Iranian MOIS Hackers Weaponize Telegram for Global Espionage Against Dissidents

The FBI has issued a public alert warning that Iranian government hackers affiliated with the Ministry of Intelligence and Security (MOIS) are actively weaponizing Telegram as a command-and-control (C2) platform to conduct espionage operations against dissidents, opposition groups, and journalists worldwide. Attack Chain: From Social Engineering to Full Device Compromise The sophisticated attack campaign begins…

Read More

Iranian Handala Hackers Breach FBI Director Kash Patel’s Personal Email Account

In a significant escalation of Iranian cyber operations against U.S. government officials, the Iran-linked hacktivist group Handala has successfully compromised the personal email account of FBI Director Kash Patel. The breach, confirmed by the FBI on March 27, 2026, resulted in the publication of photographs and documents from Patel’s Gmail account. Attack Details Handala posted…

Read More

CanisterWorm Wiper Weaponizes Trivy Supply Chain to Target Iran

A cybercrime group is attempting to leverage the ongoing US-Iran conflict by deploying a destructive wiper malware that specifically targets systems configured for Iranian users, according to new research from Krebs on Security and Aikido. TeamPCP Launches Iran-Targeting Wiper The financially motivated threat actor TeamPCP has weaponized its existing supply chain compromise to deploy CanisterWorm,…

Read More

FBI Flash Alert: Iranian Handala Hackers Weaponize Telegram for Malware C2 Operations

The FBI has issued a flash alert warning network defenders that Iranian hackers linked to the Ministry of Intelligence and Security (MOIS) are actively using Telegram as command-and-control (C2) infrastructure in malware attacks targeting journalists, dissidents, and opposition groups worldwide. Threat Actor Profile The bureau attributed these attacks to two Iranian-linked threat groups: Attack Methodology…

Read More

Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization

A comprehensive analysis by Unit 42 reveals a fundamental shift in Iranian cyber operations: state-aligned threat actors are abandoning custom malware in favor of weaponizing enterprise administrative tools to achieve unprecedented scale and stealth. The Strategic Shift During recent wiper incidents attributed to Void Manticore (Handala), attackers did not deploy novel malware or traditional compiled…

Read More

Iranian Threat Actors Target Hikvision and Dahua IP Cameras for Kinetic Strike Coordination

As Iran-Israel-US military operations escalate in the Middle East, Check Point Research and Tenable have identified a significant surge in Iranian threat actors targeting IP cameras manufactured by Hikvision and Dahua. The activity, which began spiking on February 28, 2026, coincides with the start of Operation Epic Fury and extends across Israel, Qatar, Bahrain, Kuwait,…

Read More

Pro-Iranian Hackers Expand Targeting of US Critical Infrastructure as Cyber Chaos Escalates

Pro-Iranian hackers are expanding their operations beyond the Middle East and increasingly targeting critical infrastructure in the United States, according to cybersecurity experts and recent incidents. The attacks represent a significant escalation in Iran’s cyber warfare capabilities and pose growing risks to American defense contractors, power stations, and water plants. Handala Claims Major US Attack…

Read More