Cisco Talos has seen different techniques being used by state-sponsored actors in Iran. These techniques used fake login pages, malicious apps disguised as their legitimate counterparts and BGP hijacking. The tactics outlined in this post have been in use since 2017 in an effort to gather information about Telegram and Instagram users. We declare with high confidence that these apps should be classified as “greyware” This kind of software is difficult to detect, as it typically fulfills its functions that are expected by the user (ex. send messages)”]
Source: https://blog.talosintelligence.com/2018/11/persian-stalker.html

