Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity News

Check Point researchers: Iranian hackers can bypass encrypted apps like Telegram

cybersecurity-blog
September 22, 2020

Check Point Research unraveled an ongoing surveillance operation by Iranian entities that has been targeting Iranian expats and dissidents for years. While some individual sightings of this attack were previously reported by other researchers and journalists, the investigation allowed Check Point to connect the different campaigns and attribute them to the same attackers.

Among the different attack vectors Check Point found were:

  • Four variants of Windows infostealers intended to steal the victim’s personal documents as well as access to their Telegram Desktop and KeePass account information
  • Android backdoor that extracts two-factor authentication codes from SMS messages, records the phone’s voice surroundings and more
  • Telegram phishing pages, distributed using fake Telegram service accounts

The above tools and methods appear to be mainly used against Iranian minorities, anti-regime organizations and resistance movements such as:

  • Association of Families of Camp Ashraf and Liberty Residents (AFALR)
  • Azerbaijan National Resistance Organization
  • Balochistan people

After the victim opens the document and the remote template is downloaded, the malicious macro code in the template executes a batch script which tries to download and execute the next stage payload from a Share Point site. The payload then checks if Telegram is installed on the infected machine, and if so it proceeds to extract three additional executables from its resources. 

The main features of the malware include:

  • Information Stealer
    • Uploads relevant Telegram files from victim’s computer. These files allow the attackers to make full usage of the victim’s Telegram account
    • Steals information from KeePass application
    • Uploads any file it could find which ends with pre-defined extensions
    • Logs clipboard data and takes desktop screenshots
  • Module Downloader
    • Downloads and installs several additional modules.
  • Unique Persistence
    • Implements a persistence mechanism based on Telegram’s internal update procedure

According to Check Point, the core functionality of the malware is to steal as much information as it can from the target device. The payload targets two main applications: Telegram Desktop and KeePass, the famous password manager.

Once the relevant Telegram Desktop and KeePass files have been uploaded, the malware enumerates any relevant file it can find on the victim’s computer. For each such file, the malware then uploads it after encoding the file. 

After analyzing the payload, Check Point researchers were able to find multiple variants that date back to 2014, indicating that this attack has been in the making for years. "Malware variants developed by the same attackers often have minor differences between them, especially if they are used around the same time frame. In this case however, we noticed that while some of the variants were used simultaneously, they were written in different programming languages, utilized multiple communication protocols and were not always stealing the same kind of information," the researchers say. 

The team also uncovered a malicious Android app tied to the same threat actors, which masquerades as a service to help Persian speakers in Sweden get their driver’s license. 

From the evidence gathered throughout their research, the team concluded  the threat actors, who appear to be operating from Iran, take advantage of multiple attack vectors to spy on their victims, attacking victims’ personal computers and mobile devices.

"Since most of the targets we identified are Iranians, it appears that similarly to other attacks attributed to the Islamic Republic, this might be yet another case in which Iranian threat actors are collecting intelligence on potential opponents to the regiment," say the researchers. 

David "moose" Wolpoff, a former DoD contractor who is CTO and co-founder of automated red-teaming platform Randori, was surprised at the lack of sophistication in the attack.

He notes, “It’s wrong to assume an attacker needs millions of dollars and a complex attack infrastructure to target and breach their victims. While there’s truth to that statement, the reality is that not every attack needs millions and sophisticated tools. This attack campaign was not terribly complex, but it was executed well, as proven by its six year run. A typical hacker could have gone heads-down for a weekend, set up major parts of this attack campaign, and have been reasonably successful over a period of time. The number of tools involved indicates that the attackers adapted over time, but the individual tools and techniques aren't remarkably complex, and that’s what’s impressive to me. These are all techniques and tactics I’ve used as part of red-team engagements. Quite simply, this is a case of moderate attack tools being used with well executed plans.

"When it comes to cyberespionage, attackers don't want to lose access to their tools -- they need to protect their attack infrastructure to allow for a long-running campaign. Since this campaign lasted six years, we know it was well executed; that they had a good process. Attackers cleverly took advantage of a trusted communications process. Telegram, WhatsApp and other encrypted messaging apps are good for trusted  communications, where devices and individuals trust each other to share information," he says. "But if the device on either side  is compromised, it’s reasonable to assume that an attacker sees every communication. There’s no way for a secure communication app to keep a user safe when the end devices are compromised.'

He adds, "When I think about what could have been done to prevent this attack, I’ve got a couple thoughts:

  1. If victims of this attack were using cloud-based document editing (aka Google Docs, Microsoft 365, etc), this attack couldn’t have played out as it did
  2. There are a lot of security tools that could have been deployed to defend against this attack:
    1. Cutting edge: Use Microsoft Edge in with application guard -- then the attackers would have had to use a real exploit.
    2. Cutting edge in 2009: If you had a whitelisting app downloaded, you probably would have been protected from executables running. 
    3. Cutting edge in 2001: You could even (gasp!) have had the firewall set to default deny, and had a chance to catch the malware talking to the internet.
    4. Dirt simple: Or use a Chromebook or iPad, in 2020 you can still do most of your work from these devices, and they are much more expensive to exploit.”

For more information, including detailed findings, please visit https://research.checkpoint.com/2020/rampant-kitten-an-iranian-espionage-campaign/

KEYWORDS: authentication cyber security encryption risk management surveillance

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Black laptop keyboard with white lighting

Fighting Fire with Fire: How Businesses Are Using AI to Enhance Risk Management

Police lights

Family of Fatally Shot Security Guard Seeking Answers


AlertMedia sponsored webinar

Events

September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

September 24, 2026

Physical Security Under the Microscope: The Top 4 Gaps That Fail Compliance Audits

LIVE: September 24, 2026 at 2 PM EDT Security and compliance reviews of physical security devices tend to fail for the same reasons. Learn the gaps that trip up these reviews, and why they're getting harder to ignore as scrutiny on connected devices increase. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • SEC0520-cyber-Feat-slide1_900px

    Google Researchers Warn Iranian and Chinese Hackers Targeting Presidential Candidates

    See More
  • hacker- enews

    US Government Agency Website Breached By 'Iranian' Hackers

    See More
  • Magnifying glass

    62% of phishing emails can bypass DMARC verification checks

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing