Sentinel Digital Watch | 7 October 2026
Spyware Targeting Civil Society and Phishing That Bypasses MFA
Recent spyware warnings and phishing techniques highlight continuing risks to human rights defenders, journalists and activists. This briefing explains the threats and outlines practical steps to help protect devices, accounts and sensitive communications.
Spyware targeting civil society
On 1 October 2026, Amnesty International published findings on Morocco’s use of surveillance against journalists, human rights defenders and government critics. The reporting builds on earlier investigations into Pegasus spyware targeting, including cases involving Sahrawi human rights defenders.
These cases underline the wider consequences of surveillance: compromising a defender’s device can also expose confidential sources, contacts and sensitive work.
A separate FBI advisory on HEAVYGRAM, also tracked as CHOSEN BRICK, describes Windows malware used by actors associated with Iran’s Ministry of Intelligence and Security. Authorities in the United Kingdom, United States and Netherlands have warned about a campaign targeting Iranian dissidents, journalists and opposition groups.
Attackers impersonate trusted contacts or IT support to persuade targets to install malicious software or allow remote access. The malware uses Telegram as a command-and-control channel and can steal passwords, files, communications and other sensitive information. Stolen material may be used for intelligence gathering, public exposure and reputational harm.
This does not mean Telegram itself has been compromised. In this campaign, attackers abuse a legitimate service to communicate with malware installed on a victim’s device.
How phishing can bypass MFA
Multi-factor authentication (MFA) remains an important protection, but it does not make every sign-in phishing-proof.
In an adversary-in-the-middle (AiTM) phishing attack, a fraudulent sign-in page relays the victim’s interaction with the genuine service. After the victim completes MFA, the attacker can capture the authenticated session cookie and use it to access the account without repeating the authentication process.
Microsoft’s analysis of the Tycoon2FA phishing toolkit illustrates how attackers can bypass common MFA methods, including SMS codes, one-time passwords and approval notifications.
The lesson is not to abandon MFA. It is to use phishing-resistant options where available and avoid signing in through unexpected links.
Practical steps to take now
- Telegram downloads: Review automatic media-download settings and disable automatic file downloads from untrusted conversations and groups. This reduces unwanted downloads but does not provide complete protection against spyware.
- Telegram sessions: Check Devices or Active Sessions, remove sessions you do not recognise, and enable Two-Step Verification.
- Telegram Desktop: Enable a local passcode and automatic locking. Lock your computer whenever you leave it unattended.
- Unexpected installation requests: Be cautious if someone asks you to install a “verification tool”, software update or remote-support application. Verify the request through a separate, trusted channel before acting.
- Signal contacts: Follow guidance on verifying safety numbers with important contacts, particularly before sharing sensitive information.
- Signal account protection: Enable Registration Lock, keep your Signal PIN private, and never share SMS verification codes.
- Account sign-ins: Open the official app or use a trusted bookmark instead of following an unexpected sign-in link. Where supported, use phishing-resistant MFA, such as passkeys or security keys.
Signal safety-number verification helps confirm the identity of a contact, while Registration Lock helps protect against unauthorised account registration. Neither is a spyware scan or a guarantee that a device is secure.
Sentinel Digital Watch provides digital security updates and practical guidance for human rights defenders, journalists and civil society.

