Threat Intelligence

Iran-Linked Malware Spies on Dissidents via Telegram Control

The Hacker News · 16 Sept 2026
Key Takeaway Be cautious of unsolicited files or software links sent via messaging apps, even from apparent contacts, and verify identities through a separate channel before downloading anything.

Cybersecurity agencies in the United States, United Kingdom and Netherlands have jointly detailed a Windows malware, called HEAVYGRAM by the FBI and CHOSEN BRICK by the UK's National Cyber Security Centre, that they attribute to Iran's Ministry of Intelligence and Security. The malware is controlled through the Telegram messaging app and can steal emails and chat messages, take screenshots, and secretly record audio through a device's microphone.

According to the joint advisory published on 15 September, the campaign dates back to at least autumn 2023 and has targeted people in the UK, US, Netherlands and other countries. Victims are primarily Iranian dissidents, journalists critical of the regime, activists and others whose views conflict with the government, though the FBI warns anyone considered of interest to Iran could be targeted.

The agencies say the risk extends beyond data theft: stolen screenshots and information can reveal a target's contacts, location and daily routine, and some victims' details have appeared on pro-Iranian leak sites, potentially increasing physical danger. Attacks typically begin with a message from someone posing as a known contact or tech support, designed to build trust before delivering a file disguised as legitimate software.

Iran malware Telegram espionage state-sponsored threats

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.