15-09-2026
Update on Government of Iran Cyber Actors' Deployment of Telegram C2 to Push Malware to Identified Targets
https://www.ic3.gov/CSA/2026/260915.pdf
Report completeness: High
Threats:
Heavygram
Anydesk_tool
Typosquatting_technique
Winpwnage_tool
Minidump_tool
Victims:
Iranian dissidents, Journalists opposed to iran, Opposition groups, Organizations with beliefs counter to government of iran narratives
Industry:
Government
Geo:
Iran, Iranian
TTPs:
Tactics: 3
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1016.001, T1027, T1027.013, T1036, T1056.001, T1057, T1059.003, T1059.006, T1070.004, T1071.001, have more...
IOCs:
File: 69
Url: 4
Email: 1
Path: 85
Hash: 21
Command: 5
Registry: 6
Soft:
Telegram, WhatsApp, Instagram, Embarcadero, Google Chrome, Chrome, Mozilla Firefox, Firefox, Microsoft Edge, boto3, have more...
Wallets:
mycrypto
Algorithms:
sha1, zip, hmac, md5, base64, aes-gcm, sha256, aes
Functions:
GetChromePass, ProgramGet, proc_List, sysinf, send_msg, ListOFDrive, GetFilePhone, NetTrue, create_bucket, sleep, have more...
Win API:
Dat, NoSuchProcess, AccessDenied, ZombieProcess, CryptUnprotectData, GetLastError, QueryFullProcessImageNameW
Languages:
python, delphi
Platforms:
x64, intel