Iran-Linked Malware Spies on Dissidents via Telegram Control
Cybersecurity agencies in the United States, United Kingdom and Netherlands have jointly detailed a Windows malware, called HEAVYGRAM by the FBI and CHOSEN BRICK by the UK's National Cyber Security Centre, that they attribute to Iran's Ministry of Intelligence and Security. The malware is controlled through the Telegram messaging app and can steal emails and chat messages, take screenshots, and secretly record audio through a device's microphone.
According to the joint advisory published on 15 September, the campaign dates back to at least autumn 2023 and has targeted people in the UK, US, Netherlands and other countries. Victims are primarily Iranian dissidents, journalists critical of the regime, activists and others whose views conflict with the government, though the FBI warns anyone considered of interest to Iran could be targeted.
The agencies say the risk extends beyond data theft: stolen screenshots and information can reveal a target's contacts, location and daily routine, and some victims' details have appeared on pro-Iranian leak sites, potentially increasing physical danger. Attacks typically begin with a message from someone posing as a known contact or tech support, designed to build trust before delivering a file disguised as legitimate software.