Iranian government-linked hackers are using Windows malware controlled through Telegram to spy on dissidents, journalists, activists and other people considered threats to the Iranian government. The warning comes from cybersecurity agencies in the United States, United Kingdom and Netherlands, which say the campaign is connected to Iran’s Ministry of Intelligence and Security. The malware can steal emails and chat messages, capture screenshots and access a device’s microphone to record audio. The FBI tracks the malware as HEAVYGRAM, while the UK National Cyber Security Centre calls it CHOSEN BRICK, showing the seriousness of the campaign against targets around the world.
According to the joint advisory released on September 15, the wider campaign goes back to at least the autumn of 2023, while attacks using the malware have been observed against people in the United States, United Kingdom, Netherlands and other locations since at least 2025. The main targets include Iranian dissidents, journalists who criticize Iran, activists and members of organizations whose views conflict with government narratives. However, investigators warn that the malware can potentially be used against anyone the Iranian government considers interesting or threatening. The FBI says the activity is intended to collect intelligence, leak information and cause reputational damage to targeted individuals.
The attacks usually begin with social engineering, where hackers first try to build trust with their victims. They may pretend to be someone the target knows or claim to provide technical support for a messaging platform before sending a malicious file. The attackers have disguised the malware as legitimate software and services, including Pictory, KeePass, Telegram, RunwayML, Norton Antivirus and Adobe Flash Player. In some cases, malicious files were even presented as MRI scan results to make them appear believable. The attackers often target work computers first and may then attempt to reach a victim’s personal device if corporate security blocks the attack.
Once the malicious program is installed, it creates a way for the attackers to remotely control the infected Windows computer through Telegram. The Telegram connection works as the command and control system, allowing attackers to send instructions and receive stolen information from the victim’s machine. Investigators say the malware can collect files, screenshots, emails, messages and other sensitive information, while also accessing microphones and recording audio. Using Telegram can make the malicious traffic harder to identify because the platform is already widely used for normal communication. The FBI previously warned about this activity in March 2026 and has now released additional technical details and indicators of compromise.
The threat is considered particularly serious because stolen information can expose much more than private conversations. Screenshots, messages and other collected data may reveal a person’s contacts, location, activities and daily routine. Authorities say information taken from some victims has later appeared on pro-Iranian leak websites, increasing the potential danger to those individuals. In March, the U.S. Department of Justice also seized four websites that authorities said were connected to Iranian Ministry of Intelligence and Security operations and had been used to publish stolen information and threaten journalists, dissidents and others. The agencies say Iran almost certainly uses cyber operations as part of wider efforts to suppress people it views as opponents.
The latest warning shows how attackers can combine familiar communication platforms with carefully prepared social engineering to conduct sophisticated surveillance. The FBI, UK and Dutch agencies are urging organizations and individuals to remain alert when receiving unexpected files or messages, especially from people claiming to provide technical assistance. The campaign also demonstrates why users should verify unexpected software through official sources instead of opening files sent through messaging platforms. While Telegram itself is not responsible for the malware, its infrastructure is being abused as a control channel. Authorities continue to track the campaign and have provided technical information to help defenders identify and block the malware.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news