Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
U.S., U.K., and Dutch agencies say an Iran-linked Windows malware campaign known as HEAVYGRAM and CHOSEN BRICK is used to spy on dissidents, journalists, and activists by stealing messages, screenshots, passwords, and audio. The malware spreads through deceptive files, uses Telegram for command and data theft, and has indicators tied to Iran’s MOIS, Telegram, and several cloud or proxy services. #HEAVYGRAM #CHOSENBRICK #MOIS #Telegram

Keypoints

  • HEAVYGRAM and CHOSEN BRICK are linked to Iran’s Ministry of Intelligence and Security.
  • The campaign targets dissidents, journalists, activists, and other people of interest to Iran.
  • Attackers lure victims with fake software files that run only on Windows.
  • The malware can steal chats, emails, passwords, screenshots, and microphone audio.
  • Defenders should watch for Telegram traffic, registry Run keys, and suspicious cloud or proxy connections.

Read More: https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html