Persian Stalker is targeting Iranian social media accounts.
The “group” has been around since 2017, and they have been observed targeting social media accounts. Specifically, this group focuses on gaining access and control of Instagram and Telegram accounts.
Telegram is a popular service with about 40 million users. Telegram is a communication app that has been used to organize protesters in Iran. Of course, the Iranian government is not a fan of this service. The Iranian government has actively requested that certain services and channels be shut down. As far as we know, the Iranian government has not engaged in blocking the service in Iran.
Persian Stalker uses several techniques to gain access to user’s accounts. They have created false login pages for miss-typed domain names. If you accidentally misspell the website, the malicious website will appear that looks exactly like the real thing. When the user logs in the login data are captured, and the user is presented with an error message. Of course, the 2nd login will work correctly, so the user never finds out that their login information was compromised.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Another technique that Persian Stalker uses is BGP hijacking. BGP stands for Border Gateway Protocol. BGP is the routing protocol that is used in the internet backbone. BGP is also gaining popularity as the protocol used in some wide area networks. BGP hijacking is accomplished when the routing tables are corrupted so that the attacker can maliciously reroute internet traffic. In the case of Persian Stalker, the BGP hijacking is used to capture the user’s credentials.
In summary, Persian Stalker is a malicious team who is stealing social media account usernames and passwords. They are primarily targeting Iranian users, but this target may expand to other areas of the world. This group uses the stolen information for malicious purposes. There is no evidence that this group has any political agenda.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
The 5-Minute Cyber Brief: September 11, 2026
Published: 09/11/26 Today’s pattern is management-plane root: when the systems that configure firewalls, terminate VPN, and run ERP kernels become the foothold....
SAP OVERPASS CVE-2026-44756: unauth OS command exec on NetWeaver/Web Dispatcher
What Changed SAP’s September 2026 Patch Day, with Onapsis Research Labs, shipped Security Note 3747649 for OVERPASS (CVE-2026-44756): a memory-corruption bug in...
Check Point twin CVSS 9.8s in VPN certificate path (CVE-2026-85102 / 85103)
What Changed Check Point disclosed on September 9, 2026 two critical flaws in VPN certificate handling on Quantum Security Gateway and Security...
The 5-Minute Cyber Brief: September 9, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.