Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Iranian Hackers Utilize Telegram-Controlled Malware to Conduct Widespread Surveillance of Dissidents, Journalists, and Activists




Iranian Hackers Utilize Telegram-Controlled Malware to Conduct Widespread Surveillance of Dissidents, Journalists, and Activists

In a recent joint advisory published by the National Cyber Security Center (NCSC), the Federal Bureau of Investigation (FBI), and the Netherlands' intelligence service, the AIVD, a Windows malware campaign attributed to Iran's Ministry of Intelligence and Security (MOIS) has been identified. The malware, dubbed "CHOSEN BRICK" by the U.K.'s NCSC and "HEAVYGRAM" by the FBI, has been found to be controlled via the Telegram messaging app and has been used to spy on dissidents, journalists, activists, and individuals whose views clash with the government. The joint advisory serves as a warning to users around the world about the threat posed by this malware campaign and provides necessary precautions to protect themselves from this type of cyber threat.

  • The "CHOSEN BRICK" malware campaign, attributed to Iran's Ministry of Intelligence and Security, has been identified by the FBI, NCSC, and AIVD.
  • The malware can copy emails, chat messages, take screenshots, and record audio, as well as steal passwords and data from Telegram and WhatsApp.
  • The malware has been used against targets in the US, UK, Netherlands, and worldwide since at least 2025, targeting dissidents, journalists, and activists.
  • The malware can wipe a computer and has been found on pro-Iranian leak sites, posing a risk to victims' safety.
  • The attack begins with a message posing as a trusted source, and the malware can download additional malware and delete files.
  • Signs of infection include a "Run" key entry, unexpected connections to legitimate services, and name markers set by the malware.
  • To protect yourself, do not open suspicious files, keep software up to date, and use antivirus software.
  • Network administrators should implement phishing-resistant multi-factor authentication, application allowlisting, and managed-device controls.
  • If you suspect an infection, check the "Run" key, report it to your national cyber agency, and inform your IT support.



  • In a recent joint advisory published by the National Cyber Security Center (NCSC), the Federal Bureau of Investigation (FBI), and the Netherlands' intelligence service, the AIVD, a Windows malware campaign attributed to Iran's Ministry of Intelligence and Security (MOIS) has been identified. The malware, dubbed "CHOSEN BRICK" by the U.K.'s NCSC and "HEAVYGRAM" by the FBI, has been found to be controlled via the Telegram messaging app and has been used to spy on dissidents, journalists, activists, and individuals whose views clash with the government.

    The malware is capable of copying a target's emails and chat messages, taking screenshots, and activating the microphone to record audio. It can also copy Telegram and WhatsApp data from the browser, steal saved passwords and email addresses, download additional malware, and delete files. Furthermore, at least one version of the malware can also wipe the computer.

    The malware has been found to have been used against people in the U.K., the U.S., and the Netherlands, as well as around the world, since at least 2025. The targets of this malware campaign are mainly Iranian dissidents, journalists who oppose Iran, activists, and members of groups whose views clash with the government. However, the FBI has warned that anyone Iran considers of interest could be a target.

    The danger posed by this malware campaign extends beyond stolen data. Screenshots and other collected information can show a target's contacts, location, and daily routine. The personal details of some victims have appeared on pro-Iranian leak sites, which the advisory says can increase the risk to their safety.

    In March, the U.S. Justice Department seized four such Iranian leak sites, which it said had been used to post stolen data and to call for the killing of dissidents, journalists, and others. Iran almost certainly uses this kind of cyber activity to help suppress those it sees as a threat.

    The attack begins with a message, where the attackers pose as someone the target knows or as tech support for a messaging app, building trust before sending a file that appears to be a legitimate program. The attackers often start on a target's work computer, but if that does not succeed, they try to move to a personal device, which company security does not protect.

    Reported disguises for the malware include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, and Adobe Flash Player. In some cases, the file was made to look like MRI scan results.

    When the target opens the file, a convincing fake screen appears while the real malware installs in the background. A first stage poses as the app, and a second stage connects the computer to a Telegram bot that the attackers use to control it and collect stolen data. Every version seen so far runs only on Windows.

    To survive a restart, the malware adds itself to a Windows registry "Run" key, so it starts again each time the user logs in. It also tells Microsoft Defender, the built-in antivirus, to skip certain folders so its files are not scanned.

    Each infected computer is given its own Telegram bot, which the agencies say keeps one victim's activity from mixing with another's. Once running, the malware can be told to do many things: list running programs, take screenshots, turn on the microphone, copy Telegram and WhatsApp data from the browser, steal saved passwords and email addresses, download additional malware, and delete files. At least one version can also wipe the computer.

    The malware has not been seen spreading across a network on its own, though it can download more tools. Stolen files leave the computer through the Telegram bot and through cloud storage services such as Vultr and Storj. Newer versions send their Telegram traffic through proxy servers to hide it.

    Signs to Look For
    The advisories list signs that defenders and at-risk users can check for, including a "Run" key entry named SMQDService or winappx, added so the malware starts at login, a folder with an added space, C:\Windows \SysWOW64, where the malware drops extra files, unexpected connections to otherwise-legitimate services, including api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net, and name markers the malware sets to avoid running twice, such as ytyjyujyu and noi672pp434awkc12f.

    How to Protect Yourself
    To lower the risk, the agencies recommend that individuals do not open files sent through messages or links, and download software only from official websites or app stores. They also recommend keeping the operating system and all apps up to date, ideally with automatic updates. Running antivirus software and keeping it switched on and current is also advised. Not ignoring SmartScreen warnings when downloading files is also recommended.

    Network administrators are advised to turn on phishing-resistant multi-factor authentication, use application allowlisting and managed-device controls, use the scanning and security tools their email provider offers, monitor computers and network traffic, and search logs for the indicators above.

    Anyone who suspects an infection should check the "Run" key described above, tell their IT support, and report it to their national cyber agency. The advisories do not say whether removing the malware alone clears a compromise.

    The joint advisory published by the NCSC, the FBI, and the AIVD serves as a warning to users around the world about the threat posed by this malware campaign. It is essential for individuals and organizations to take the necessary precautions to protect themselves from this type of cyber threat.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Iranian-Hackers-Utilize-Telegram-Controlled-Malware-to-Conduct-Widespread-Surveillance-of-Dissidents-Journalists-and-Activists-ehn.shtml

  • https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html


  • Published: Tue Sep 15 13:49:47 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us