Skip to main content

Iran hackers reveal identities of 15m Telegram messaging accounts

Hacking group Rocket Kitten, with alleged links to Republican Guard, believed to be behind the hack
Iranian youth use computers in Qom with portraits of the Islamic Republic's late founder Ayatollah Ruhollah Khomeini (L) and Supreme Leader Ayatollah Ali Khamenei (R) in the background (AFP)

By Joseph Menn and Yeganeh Torbati

Iranian hackers have compromised more than a dozen accounts on the Telegram instant messaging service and identified the phone numbers of 15 million Iranian users, the largest known breach of the encrypted communications system, cyber researchers told Reuters on Tuesday.

The attacks, which took place this year and have not been previously reported, jeopardised the communications of activists, journalists and other people in sensitive positions in Iran, where Telegram is used by some 20 million people, said independent cyber researcher Collin Anderson and Amnesty International technologist Claudio Guarnieri, who have been studying Iranian hacking groups for three years.

While Facebook and Twitter are banned in Iran, Telegram is widely used by groups across the political spectrum. They shared content on Telegram "channels" and urged followers to vote ahead of Iran's parliamentary elections in February 2016.

Telegram promotes itself as an ultra-secure instant messaging system because all data is encrypted from start to finish, known in the industry as end-to-end encryption. A number of other messaging services, including Facebook Inc's WhatsApp, say they have similar capabilities.

Headquartered in Berlin, Telegram says it has 100 million active subscribers and is widely used in the Middle East, including by the Islamic State militant group, as well as in Central and Southeast Asia, and Latin America.

Telegram's vulnerability, according to Anderson and Guarnieri, lies in its use of SMS text messages to activate new devices. When users want to log on to Telegram from a new phone, the company sends them authorisation codes via SMS, which can be intercepted by the phone company and shared with the hackers, the researchers said.

Armed with the codes, the hackers can add new devices to a person's Telegram account, enabling them to read chat histories as well as new messages.

"We have over a dozen cases in which Telegram accounts have been compromised, through ways that sound like basically coordination with the cellphone company," Anderson said in an interview.

Telegram's reliance on SMS verification makes it vulnerable in any country where mobile phone companies are owned or heavily influenced by the government, the researchers said.

A spokesman for Telegram said customers can defend against such attacks by not just relying on SMS verification. Telegram allows - though it does not require - customers to create passwords, which can be reset with so-called "recovery" emails.

"If you have a strong Telegram password and your recovery email is secure, there's nothing an attacker can do," said Markus Ra, the spokesman.

Iranian officials were not available to comment. Iran has in the past denied government links to hacking.

Rocket Kitten

The Telegram hackers, the researchers said, belonged to a group known as Rocket Kitten, which used Persian-language references in their code and carried out "a common pattern of spear phishing campaigns reflecting the interests and activities of the Iranian security apparatus."

Anderson and Guarnieri declined to comment on whether the hackers were employed by the Iranian government. Other cyber experts have said Rocket Kitten's attacks were similar to ones attributed to Iran's powerful Revolutionary Guards.

The researchers said the Telegram victims included political activists involved in reformist movements and opposition organisations. They declined to name the targets, citing concerns for their safety.

"We see instances in which people ... are targeted prior to their arrest," Anderson said. "We see a continuous alignment across these actions."

The researchers said they also found evidence that the hackers took advantage of a programming interface built into Telegram to identify at least 15 million Iranian phone numbers with Telegram accounts registered to them, as well as the associated user IDs. That information could provide a map of the Iranian user base that could be useful for future attacks and investigations, they said.

"A systematic de-anonymisation and classification of people who employ encryption tools (of some sort, at least) for an entire nation" has never been exposed before, Guarnieri said.

Cyber experts say Iranian hackers have become increasingly sophisticated, able to adapt to evolving social media habits. Rocket Kitten's targets included members of the Saudi royal family, Israeli nuclear scientists, NATO officials and Iranian dissidents, US-Israeli security firm Check Point said last November.

Telegram was founded in 2013 by Pavel Durov, known for starting VKontakte, Russia's version of Facebook, before fleeing the country under pressure from the government.

New MEE newsletter: Jerusalem Dispatch

Sign up to get the latest insights and analysis on Israel-Palestine, alongside Turkey Unpacked and other MEE newsletters

Middle East Eye delivers independent and unrivalled coverage and analysis of the Middle East, North Africa and beyond. To learn more about republishing this content and the associated fees, please fill out this form. More about MEE can be found here.