Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Iranian intelligence services are using a Telegram-controlled malware, dubbed HEAVYGRAM/CHOSEN BRICK, to spy on dissidents, journalists, and activists worldwide. The malware, spread through deceptive messages and disguised files (including mimicking legitimate apps like Pictory and Norton Antivirus), steals data, takes screenshots, and records audio. The agencies have seized Iranian leak sites used to disseminate stolen information and call for violence against targeted individuals. Users and administrators should implement robust security measures, including multi-factor authentication, application allowlisting, and diligent monitoring for specific indicators of compromise.
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have issued a joint advisory detailing a Windows malware campaign orchestrated by Iran's Ministry of Intelligence and Security (MOIS). The malware, known as HEAVYGRAM/CHOSEN BRICK, is used to spy on individuals deemed a threat by the Iranian government, including dissidents, journalists, and activists.
What happened
The campaign began in the autumn of 2023 and has been ongoing since at least 2025. The malware is controlled via Telegram, where attackers pose as known contacts or tech support to deliver deceptive files that appear to be legitimate programs. These files are often disguised as apps like Pictory, KeePass, and Norton Antivirus. Once opened, the malware installs silently while a convincing fake screen appears.
After installation, the malware connects to a Telegram bot, which allows the attackers to remotely control the infected device and steal data. The malware can then perform a wide range of actions, including listing running programs, taking screenshots, activating the microphone, copying Telegram and WhatsApp data from the browser, stealing saved passwords and email addresses, downloading additional malware, and in some cases, wiping the computer. The malware is designed to survive reboots by adding itself to a Windows registry "Run" key. It also bypasses antivirus software by skipping certain folders.
To evade detection, newer versions of the malware now use proxy servers to mask their Telegram traffic. Stolen files are then transmitted through Telegram and cloud storage services such as Vultr and Storj. The agencies have taken steps to combat the spread of this malware by seizing Iranian leak sites that have been used to post stolen data and promote violence.
Technical details
The malware is exclusively for Windows and has been seen spreading across a network, but it doesn't spread on its own; it downloads additional tools. The malware uses various indicators of compromise, including:
- Registry key: a "Run" key entry named SMQDService or winappx, added so the malware starts at login.
- File path: a folder with an added space, C:\Windows\SysWOW64, where the malware drops extra files.
- Network: unexpected connections to otherwise-legitimate services, including api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net.
- Mutex: name markers the malware sets to avoid running twice, such as ytyjyujyu and noi672pp434awkc12f.
Impact
The primary impact is the compromise of sensitive information belonging to targeted individuals, including personal data, communications, and potentially, their safety. The dissemination of stolen information through Iranian leak sites has fueled calls for violence and further endangered those targeted. The campaign represents a significant threat to human rights and freedom of expression.
What to do
- Do not open files sent through messages or links, and download software only from official websites or app stores.
- Keep the operating system and all apps up to date, ideally with automatic updates.
- Run antivirus software and keep it switched on and current.
- Do not ignore SmartScreen warnings when downloading files.
For network administrators:
- Turn on phishing-resistant multi-factor authentication.
- Use application allowlisting and managed-device controls.
- Use the scanning and security tools your email provider offers.
- Monitor computers and network traffic, and search logs for the indicators above.
Anyone who suspects an infection should check the "Run" key described above, tell their IT support, and report it to their national cyber agency. The agencies state that removing the malware alone may not clear a compromise.
Why it matters
The campaign highlights Iran's use of cyber espionage to suppress dissent and protect its political interests. The coordinated effort to disseminate stolen information underscores the broader threat posed by state-sponsored actors engaging in cyber operations to undermine human rights and freedom of expression globally.
