Intelligence agencies from the U.S., U.K., and the Netherlands have identified a Windows-based malware, known as HEAVYGRAM or CHOSEN BRICK, used by Iran to surveil global dissidents and journalists.
Key Points
- The malware is controlled via Telegram and can record audio, capture screenshots, and steal sensitive data like emails and passwords.
- Attributed to Iran’s Ministry of Intelligence and Security (MOIS), the campaign has targeted activists and journalists worldwide since at least 2023.
- Attackers disguise the malware as legitimate software, including KeePass, Norton Antivirus, and various AI tools, to trick users into installing it.
- Once active, the malware persists by modifying Windows registry keys and can be instructed to wipe files or download additional malicious tools.
- Security agencies recommend using phishing-resistant multi-factor authentication and avoiding files from untrusted sources to mitigate infection risks.