AUTO-UPDATED

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Intelligence agencies from the U.S., U.K., and the Netherlands have identified a Windows-based malware, known as HEAVYGRAM or CHOSEN BRICK, used by Iran to surveil global dissidents and journalists.

Key Points

  • The malware is controlled via Telegram and can record audio, capture screenshots, and steal sensitive data like emails and passwords.
  • Attributed to Iran’s Ministry of Intelligence and Security (MOIS), the campaign has targeted activists and journalists worldwide since at least 2023.
  • Attackers disguise the malware as legitimate software, including KeePass, Norton Antivirus, and various AI tools, to trick users into installing it.
  • Once active, the malware persists by modifying Windows registry keys and can be instructed to wipe files or download additional malicious tools.
  • Security agencies recommend using phishing-resistant multi-factor authentication and avoiding files from untrusted sources to mitigate infection risks.

Why it Matters

This campaign highlights the increasing use of encrypted messaging platforms like Telegram as command-and-control infrastructure for state-sponsored espionage. By targeting personal devices, these intelligence operations pose a direct physical and digital safety risk to activists and journalists operating outside of Iran.
Internet Published by info@thehackernews.com (The Hacker News)
Read original