Alerts & Notice

  1. Public

    Security Alert: Telegram "Session-Grabber" Phishing Adds Fake "Microsoft Teams" Meetings — and Leaves a Traceable Device Fingerprint

    Following our 10 June 2026 alert on the real-time Telegram/WhatsApp "session-grabber" campaign targeting Iranian journalists and civil-society figures, CERTFA has confirmed the operation is active and evolving. The operator now lures targets with a counterfeit "Microsoft Teams" online meeting — delivered over WhatsApp/Telegram from an impersonated known contact, sometimes reinforced with an AI-cloned voice note — and hosts each lure on a disposable Cloudflare Quick Tunnel (hxxps[:]//<random-words>[.]trycloudflare[.]com) or on the same homoglyph domain teiegram[.]site (a look-alike of "telegram" using a capital I in place of the lowercase l, so it renders as "telegram" while remaining pure ASCII with no browser warning). The core mechanism is unchanged and unchanged-ly dangerous: the "meeting" page never connects to a real service — when the target clicks to join, the operator's server begins a genuine Telegram login as the victim, Telegram sends the real one-time code to the victim's own device, and the victim types that code (and, if prompted, their two-step-verification password) into the fake page, handing the operator a live, portable session that defeats SMS- and app-based one-time codes. This update reports two new findings: a second confirmed victim in the Iranian diaspora, and — most useful for the community — the exact device fingerprint the operator's client leaves behind in a hijacked account's Active Sessions list, which anyone can check for themselves.

    read more about Security Alert: Telegram "Session-Grabber" Phishing Adds Fake "Microsoft Teams" Meetings — and Leaves a Traceable Device Fingerprint
  2. Public

    Security Alert: Telegram & WhatsApp "Session-Grabber" Phishing Targeting Iranian Journalists

    A real-time account-takeover ("session-grabber") campaign is hijacking the Telegram and WhatsApp accounts of Iranian journalists and civil-society figures. The operator makes contact over WhatsApp while impersonating someone the target knows, then sends a link to a counterfeit Telegram "Private Chat" page hosted on a homoglyph domain — teiegram[.]site, which displays as "Telegram.site" because the lowercase "l" is replaced by a capital "I" (teIegram). The page induces the victim to relay the genuine Telegram login code sent to their device and, in a second step, their Two-Step Verification (2FA) cloud password — handing the operator full control of the account within seconds. The same server hosts a parallel WhatsApp phishing kit. Because the homoglyph is pure ASCII, it produces no punycode and triggers no browser warning.

    read more about Security Alert: Telegram & WhatsApp "Session-Grabber" Phishing Targeting Iranian Journalists
  3. Public

    Security Alert: IranGuard Spyware Campaign

    A spear-phishing campaign is distributing surveillance malware named "IranGuard" targeting Iranian individuals and organizations. The malware is delivered via spear-phishing emails impersonating the "Etelaat Faraja" (فرماندهی اطلاعات فراجا - FARAJA Intelligence Command), an Iranian law enforcement intelligence agency. The campaign distributes both Android (APK) and Windows (EXE) variants of the spyware, providing comprehensive surveillance capabilities across both mobile and desktop platforms.

    read more about Security Alert: IranGuard Spyware Campaign
  4. Public

    Mobile Phone: New Android Surveillance Malware Targeting Persian Speakers

    A malicious Android application disguised as a mobile phone utility was recently shared with our team at CERTFA Lab. Upon analysis, we discovered this sample to be a sophisticated surveillance tool with strong indicators linking it to Domestic Kitten (APT-C-50), an Iranian state-backed hacking group associated with the Islamic Revolutionary Guard Corps (IRGC).

    read more about Mobile Phone: New Android Surveillance Malware Targeting Persian Speakers
  5. Public

    Document.exe: New malicious Word file by Iranian state-backed hackers

    In the past few days, a malicious Word document sample, believed to be linked to Iranian state-backed hackers, was shared with our team at CERTFA Lab by a community member. Upon the initial analysis, we discovered that this sample includes an OLE object and an AutoOpen macro, which read and decode obfuscated text from UserForm1.TextBox1 into ASCII characters, and then converted from base64 to drop a payload onto the victim's system at C:\Users\Public\Document.exe.

    read more about Document.exe: New malicious Word file by Iranian state-backed hackers