FBI Issues Warnings on Russian and Iranian Cyber Operations Targeting Messaging Platforms

FBI Alerts to Russian Cyber Espionage

TheThe Federal Bureau of Investigation (FBI) recently released two distinct warnings concerning cyber activities originating from Russia and Iran, both of which involve the exploitation of popular messaging applications.

Russian intelligence agencies are reportedly targeting commercial messaging apps, such as Signal, to gain unauthorized access to accounts belonging to current and former U.S. government officials, military personnel, political figures, and journalists. The FBI, in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), stated that this global operation has led to the unauthorized compromise of thousands of accounts.

The Russian operatives are employing phishing tactics, sending messages designed to appear as legitimate automated support notifications. These messages aim to trick recipients into believing they need to perform an action, such as clicking a link or providing verification codes and account PINs. Should a user comply with these requests, they inadvertently grant the attackers unauthorized access to their account, either by linking the attacker's device or by facilitating a complete account takeover. The agencies noted that as this campaign evolves, additional methods, including malware, might be used to infect victims.

Once an account is compromised, the malicious actors can view the victim's messages and contact lists, send messages, and initiate further phishing attempts against other messaging accounts. While the advisory specifically highlights Signal, the FBI emphasized that these tactics could be applied to any messaging application. The public is urged to exercise caution with unverified messages and to enhance their personal cybersecurity practices. The advisory clarifies that these campaigns do not exploit vulnerabilities within Signal or other messaging apps; instead, they are designed to bypass encryption by directly compromising the users themselves.

Last year, during congressional testimony, Director of National Intelligence Tulsi Gabbard referenced CISA's guidance, issued after Chinese hackers breached U.S. telecom networks. This guidance advised "highly targeted individuals" to utilize "end-to-end encrypted communications." She also pointed out that Signal comes pre-installed on federal government devices. In December, President Donald Trump signed a Pentagon policy bill mandating that the Defense secretary ensure senior Department of Defense (DOD) leaders are provided with mobile phones equipped with "enhanced cybersecurity protections," including data encryption.

Previously, the Pentagon's inspector general issued a report indicating that Defense Secretary Pete Hegseth violated existing departmental regulations for handling sensitive information and potentially endangered troops. This occurred when he used Signal to discuss the then-imminent U.S. military strike in Yemen. Following President Donald Trump's inauguration last year, The Atlantic published a complete transcript of a Signal conversation among Cabinet-level officials preceding a strike on the Houthi armed group in Yemen. This happened after a journalist was mistakenly included in the chat, where members openly discussed strike timings and the types of aircraft involved. Another watchdog report concluded that the Defense Department lacks a secure messaging platform capable of coordinating sensitive operations.

Iranian Cyber Operations: Handala Hack and Telegram Exploitation

In a separate flash alert issued on Friday, the FBI detailed how Iran's Ministry of Intelligence and Security (MOIS) is leveraging the messaging platform Telegram as infrastructure to communicate with malware. This malware is used to infect the devices of Iranian dissidents, journalists, and other targeted individuals.

This malware enables MOIS to steal information and monitor its targets. The threat actors disguised the malware to appear as commonly used programs or services on Windows machines. Infected devices are then connected to bots on Telegram, which facilitate remote user access to exfiltrate screen captures or files from the victim's devices. The FBI directly linked the use of Telegram to the alleged Iranian group known as Handala Hack, which recently claimed responsibility for an attack on the medical device company Stryker.

The agency reported that in some instances, the malware initially mimicked legitimate applications such as the AI video generator Pictory, the password manager KeePass, or Telegram itself. Once opened, it connected to a government-controlled Telegram bot, establishing "bidirectional communication between the compromised device and api.telegram[.]org." At least one victim was contacted via social media messaging apps by hackers posing as technical support for the application. The Iranian cyber actors then persuaded the victim to accept a file transfer containing the disguised stage 1 malware.

Upon gaining initial access to the victim's system, additional malware was downloaded. This malware allowed for capabilities such as screen and audio recordings, cache captures, file compression, and file deletion. The advisory noted, "Based on multiple observations, stage 1 of the malware appeared to be tailored to the victim's pattern of life to increase likelihood of victim downloading the malware, which indicates the Iranian cyber actors likely performed target reconnaissance prior to engaging with the victim."

Several experts have observed that the use of Telegram as a crucial component in cyber compromises is an increasing trend among cybercriminals and state-backed actors, who utilize it as command-and-control infrastructure. Ensar Seker, CISO at SOCRadar, explained that Telegram allows threat actors to integrate malicious traffic within trusted, encrypted platforms. Seker stated, "By leveraging a widely used application like Telegram, groups such as Handala significantly reduce the likelihood of detection, because security controls are often tuned to allow this traffic by default." He added, "The bigger implication is that encrypted messaging platforms are becoming dual-use infrastructure for both communication and covert operations. Security teams need to reassess their trust assumptions and implement visibility controls around sanctioned apps, including logging, anomaly detection, and strict access policies."

Start using Conzent today

Privacy-first consent management for modern websites.