Cybersecurity & Privacy

Global Intelligence Agencies Expose Iranian State-Sponsored Malware Campaign Targeting Dissidents and Journalists via Telegram

In an unprecedented joint intelligence disclosure, cybersecurity and law enforcement agencies from the United States, the United Kingdom, and the Netherlands have released comprehensive technical details regarding a sophisticated Windows-based spyware campaign orchestrated by the Iranian government. Specifically attributed by the Federal Bureau of Investigation (FBI) to Iran’s Ministry of Intelligence and Security (MOIS), the malicious software is weaponized to surveil, track, and intimidate political dissidents, independent journalists, and human rights activists operating on an international scale.

The collaborative advisory—published jointly by the U.K.’s National Cyber Security Center (NCSC), the FBI, and the Dutch General Intelligence and Security Service (AIVD)—sheds light on an invasive espionage operation designed to bypass standard digital security protections. Designated as HEAVYGRAM by American authorities and CHOSEN BRICK by British counterparts, the Windows malware functions primarily through the popular cloud-based messaging application Telegram. By leveraging legitimate communication channels for command-and-control (C2) operations, the threat actors maintain a persistent surveillance foothold on infected workstations and personal devices, posing severe physical and digital threats to targeted individuals worldwide.

Anatomy of the HEAVYGRAM and CHOSEN BRICK Malware

The technical architecture of the HEAVYGRAM/CHOSEN BRICK spyware suite is engineered for deep, covert surveillance. Once successfully deployed onto a target’s Windows-based computer, the malware establishes discrete communication pathways using dedicated Telegram bots assigned uniquely to each infected machine. This compartmentalized approach ensures that the operational data harvested from one victim does not cross-contaminate or expose the broader intelligence network if compromised.

The capabilities of the malware extend far beyond standard credential theft. According to the updated technical analysis released by the FBI, the spyware can execute real-time audio surveillance by forcibly activating the host device’s microphone. Furthermore, it systematically logs keystrokes, extracts saved passwords and email addresses, clones locally cached chat histories and contact lists from web-browser instances of messaging applications like Telegram and WhatsApp, and captures high-resolution screenshots.

To maintain persistence across system reboots, the malware aggressively alters the Windows registry, embedding itself within the system’s "Run" keys to ensure execution upon every user login. Concurrently, the spyware interacts with local security configurations, instructing built-in utilities like Microsoft Defender to bypass specific directories, thereby rendering its own payloads invisible to routine anti-malware scans. Exfiltrated intelligence—including sensitive documents, location data, and communication logs—is funneled back through the Telegram C2 infrastructure or routed via external cloud storage providers such as Vultr and Storj. In advanced iterations observed by researchers, the malicious traffic is further obfuscated using intermediary proxy servers to mask the origin of the network requests.

Chronology and Evolution of the Espionage Campaign

The origins of this state-sponsored surveillance operation trace back to the autumn of 2023, during which Iranian intelligence actors began laying the groundwork for targeted cyber intrusions against individuals deemed critical of the regime in Tehran. While the initial phases of the campaign focused on localized spear-phishing and social engineering, the deployment of the CHOSEN BRICK malware framework expanded significantly by 2025, reaching targets across North America, Europe, and various regions globally.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The campaign came to public prominence in March 2026, when the FBI issued an initial security alert warning of Iranian cyber actors utilizing Telegram-based C2 mechanisms to compromise high-profile targets. This disclosure prompted international cybersecurity partners to initiate deep-dive forensic investigations into the malware’s delivery mechanisms and operational infrastructure.

Throughout the campaign, the threat actors demonstrated a high degree of patience and sophistication in their delivery methods. Initial contact is typically established through social engineering. Attackers pose as trusted acquaintances, colleagues, or technical support representatives for messaging platforms, slowly building rapport before transmitting malicious files disguised as legitimate software installers.

To trick targets into executing the payload, the malware is routinely bound to convincing decoys. Documented disguises include popular desktop applications and utilities such as the AI video creation platform Pictory, password manager KeePass, RunwayML, Norton Antivirus, Adobe Flash Player, and customized Telegram desktop wrappers. In particularly aggressive instances tailored for specific high-value targets, the malicious executables were masked as confidential medical documents, including fake MRI scan results. When opened, the decoy application displays a realistic user interface while quietly installing the multi-stage spyware in the background.

Broader Geopolitical Implications and Physical Threats

Intelligence analysts emphasize that the risks associated with HEAVYGRAM and CHOSEN BRICK transcend traditional digital espionage. The theft of personal data, routine schedules, geolocation records, and private communications directly exposes dissidents and journalists to severe physical danger.

In many cases, harvested intelligence has been weaponized and published on pro-Iranian leak sites designed to intimidate, harass, and incite violence against regime critics living abroad. The coordinated dissemination of personal information on these platforms is viewed by security agencies as part of a broader, state-sanctioned psychological operations strategy intended to silence opposition voices outside Iran’s borders.

The gravity of these operations led to decisive law enforcement action in March 2026, when the United States Department of Justice successfully seized four primary Iranian-linked leak sites. Prosecutors stated that these platforms were actively utilized not only to host stolen data resulting from cyber breaches—including historical intrusions linked to government and corporate entities—but also to host targeted calls for violence and targeted assassinations against prominent journalists and human rights defenders.

International security agencies have repeatedly highlighted that Iran’s offensive cyber operations frequently intersect with kinetic intelligence activities. Historical precedents indicate that digital reconnaissance gathered through malware campaigns has routinely served as foundational intelligence for physical harassment, intimidation campaigns, and transnational repression plots, including attempted kidnappings and assassinations orchestrated by MOIS operatives across Western nations.

Official Responses and Industry Accountability

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

As the global cybersecurity community grapples with the proliferation of state-sponsored spyware, technology platforms and international regulatory bodies face mounting pressure to mitigate abuse. Following the initial FBI warnings regarding the weaponization of Telegram for command-and-control operations, representatives from Telegram emphasized the platform’s commitment to user safety. Company spokespersons noted that platform moderators actively monitor and routinely remove user accounts, channels, and bots identified as participating in malware distribution or malicious operations.

Despite these enforcement actions, cybersecurity experts note that decentralized and encrypted communication channels present persistent challenges for platform moderation, requiring continuous collaboration between private technology firms and government intelligence bodies.

Defensive Recommendations and Mitigation Strategies

In response to the multi-agency advisories, cybersecurity professionals and government institutions have issued comprehensive mitigation guidelines aimed at both individual users at high risk and enterprise network administrators.

For high-risk individuals—such as investigative journalists, activists, and political dissidents—the advisories recommend:

  • Exercising extreme caution when receiving unsolicited files, documents, or software updates, even when they appear to originate from trusted contacts.
  • Utilizing hardware security keys and multi-factor authentication (MFA) secured against SIM-swapping and session-hijacking.
  • Regularly auditing device autorun configurations, scheduled tasks, and Windows registry keys for unauthorized modifications.
  • Implementing robust, endpoint detection and response (EDR) solutions on personal devices where feasible, rather than relying solely on default operating system protections.

For network administrators and organizational security teams:

  • Monitoring outbound network traffic for anomalous connections directed toward cloud storage providers like Vultr and Storj, as well as unauthorized proxy routing.
  • Restricting the execution of unverified binaries and enforcing strict application whitelisting policies.
  • Regularly reviewing system logs for unauthorized alterations to Windows Defender exclusion lists and registry "Run" keys.
  • Establishing secure, out-of-band communication channels for reporting suspected compromise and coordinating incident response.

As threat actors continue to refine their tradecraft, integrating commodity tools and encrypted messaging platforms into advanced espionage frameworks, the joint advisory serves as a critical reminder of the intersection between digital security and physical safety in modern geopolitical conflict. Organizations and individuals operating within high-risk environments are urged to consult the complete technical indicators of compromise published by the FBI and the NCSC to safeguard their digital infrastructure against state-sponsored intrusion.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.