Bottom line: Iranian hackers are using a Windows malware controlled by Telegram to spy on high-profile targets globally.
What's happening: Iranian hackers have linked the malware to the Iranian intelligence service, which has been linked to attacks on dissidents, journalists, and activists in Iran and beyond, including the 2019 hacking of the Iranian opposition website, "Tasnim News Agency."
What to do: US, UK, and Dutch security leaders should ensure their Windows systems are up-to-date with the latest security patches and monitor their networks for suspicious activity, particularly around Telegram usage.