Threat Intelligence

Iran’s intelligence service uses Telegram-controlled malware to spy on dissidents

Cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have detailed a Windows malware, known as HEAVYGRAM or CHOSEN BRICK, that is allegedly used by Iran's intelligence service to spy on dissidents, journalists, and activists globally. The malware leverages the Telegram messaging app for command and control, enabling it to steal sensitive information and compromise target devices, based on information published by The Hacker News.

The malware, attributed to Iran's Ministry of Intelligence and Security (MOIS), has been active since at least 2025, targeting individuals critical of the Iranian government. The attack begins with social engineering, where attackers pose as trusted contacts or tech support to trick victims into downloading malicious files disguised as legitimate software. Once executed, the malware installs covertly, establishing a connection to a Telegram bot controlled by the attackers. This allows for extensive data exfiltration, including emails, chat messages, screenshots, and audio recordings via the microphone. The collected data can reveal personal details, contacts, and daily routines, with some victims' information appearing on pro-Iranian leak sites, increasing their safety risks.

The agencies also noted that the malware can be instructed to download additional malicious payloads or even wipe the infected computer. To protect against such threats, individuals are advised to be cautious with file downloads and keep software updated, while network administrators should implement robust security measures like multi-factor authentication and network monitoring.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds