Online Security & Privacy

Global Cybersecurity Coalition Exposes Sophisticated Iranian Malware Campaign Targeting Dissidents and Journalists Worldwide

A collaborative investigation by the United States Federal Bureau of Investigation (FBI), the United Kingdom’s National Cyber Security Centre (NCSC), and the Netherlands’ General Intelligence and Security Service (AIVD) has uncovered a sophisticated, state-sponsored cyber-espionage operation originating from Iran. The campaign, which has been active since at least the autumn of 2023, utilizes a highly capable Windows-based malware strain to systematically surveil and compromise the digital lives of activists, journalists, and political dissidents across the globe.

The malware, identified by the FBI as HEAVYGRAM and by the NCSC as CHOSEN BRICK, is uniquely characterized by its reliance on the Telegram messaging platform for command-and-control (C2) operations. This architecture allows Iranian intelligence actors—specifically those linked to the Ministry of Intelligence and Security (MOIS)—to remotely exfiltrate sensitive data, including encrypted chat logs, email correspondence, and private documents, while also granting the attackers real-time access to the victim’s hardware, such as microphone audio and screen captures.

A Chronology of the Espionage Campaign

The origins of this campaign can be traced back to the final quarter of 2023, a period marked by heightened tensions in the Middle East and an intensification of Iranian state efforts to silence domestic and international dissent. While initial technical indicators were detected by cybersecurity researchers in late 2023, it was not until March 2026 that the FBI issued its first formal alert regarding the MOIS’s use of Telegram-based C2 infrastructure to deploy malware.

The September 15, 2026, joint advisory represents the most comprehensive assessment of the threat to date. It highlights a tactical shift in Iranian cyber operations, moving away from rudimentary phishing to highly targeted, social engineering-heavy campaigns. The agencies confirmed that since 2025, the reach of CHOSEN BRICK has expanded significantly, affecting high-profile targets within the U.K., the U.S., and various European jurisdictions. This escalation signals a persistent commitment by the MOIS to track individuals regardless of their geographic location, viewing them as existential threats to the Iranian state.

Technical Anatomy of the Attack

The sophistication of this malware lies not in its complexity, but in its psychological effectiveness. The attack chain invariably begins with the establishment of trust. Adversaries typically adopt the persona of a trusted colleague, a fellow activist, or, in more advanced cases, technical support personnel for popular messaging services.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Once a rapport is established, the attacker delivers a malicious payload disguised as legitimate software. The disguises are meticulously crafted to mirror essential tools, including the AI-driven video editor Pictory, the open-source password manager KeePass, and productivity suites like RunwayML. In instances where the target is a high-value individual, the malware has been hidden within files masquerading as sensitive documents, such as medical MRI scans, to trigger an immediate, emotionally driven response that bypasses cautious behavior.

When the user executes the file, a dual-stage deployment process occurs. The first stage presents a convincing, benign interface to the user—often a functional version of the software being spoofed—to avoid suspicion. Simultaneously, in the background, the second stage initiates a silent connection to a Telegram bot. By utilizing Telegram as the C2 channel, the attackers effectively bypass many traditional network-based security filters, as traffic to the platform is often categorized as trusted or benign by enterprise firewalls.

The malware is persistent; it modifies the Windows registry to ensure that it executes automatically upon every system boot. Furthermore, it actively attempts to subvert Microsoft Defender by adding exclusions for its own malicious directories, effectively blinding the host’s primary line of defense. Each infected system is assigned a unique Telegram bot, a strategy that compartmentalizes data and ensures that if one bot is discovered and neutralized by security researchers, the broader campaign remains undetected.

Strategic Implications and Human Cost

The implications of this campaign extend far beyond the theft of digital credentials. The intelligence gathered—ranging from contact lists and private calendars to real-time location data—is frequently utilized to orchestrate physical harm. The advisory underscores a disturbing pattern where information stolen via malware is subsequently uploaded to pro-Iranian "leak sites." These platforms serve a dual purpose: they act as a repository for stolen data and as a public "hit list," often featuring calls for the harassment, kidnapping, or assassination of those identified as enemies of the state.

The U.S. Justice Department’s disruption of four such sites in March 2026 was a critical tactical win, yet the underlying threat remains fluid. The ability to monitor a target’s daily routine provides Iranian intelligence with the situational awareness necessary to conduct "kinetic" operations—physical actions taken against individuals residing in foreign countries. This transition from cyber-espionage to the facilitation of real-world violence represents a significant escalation in the scope of state-sponsored cyber warfare.

Defensive Posture and Mitigation

For individuals and organizations at risk, the joint advisory provides a roadmap for mitigation. The core recommendation remains the implementation of strict "zero trust" protocols, particularly regarding the execution of files from unverified or social media-based sources.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

For network administrators, the following measures are deemed essential:

  1. Endpoint Monitoring: Implementing robust EDR (Endpoint Detection and Response) solutions that can flag unauthorized modifications to the Windows Registry and detect anomalous connections to external Telegram bot APIs.
  2. Traffic Analysis: Monitoring for outbound traffic to cloud storage services like Vultr and Storj, which are frequently used by the malware to stage large data exfiltrations.
  3. Behavioral Baselines: Establishing strict policies against the use of unauthorized software, particularly in high-risk professional environments.
  4. Regular Audits: Periodically scanning for the presence of the specific "Run" registry keys associated with known variants of CHOSEN BRICK.

The FBI and its international partners emphasize that while removing the malware is a necessary first step, a compromised system must be considered "burned." Any device that has been infected should ideally be wiped and re-imaged, as the malware possesses the capability to download secondary, more persistent payloads that may survive simple file deletion.

Future Outlook

The collaboration between the FBI, NCSC, and AIVD reflects a growing trend in international security: the "naming and shaming" of state actors to deter further aggression. By publishing technical indicators, including file hashes and specific command structures, the agencies hope to force the MOIS to expend significant resources on retooling, thereby reducing the efficiency of their operations.

However, as long as the political incentives for Iran to monitor its diaspora remain high, the use of such tools is unlikely to cease. The democratization of malware-as-a-service and the use of legitimate platforms like Telegram for malicious ends present a permanent challenge to modern digital security. For activists, journalists, and dissidents, the primary lesson of this campaign is that the barrier between digital privacy and physical safety has effectively dissolved, necessitating a level of operational security that was once the exclusive domain of state intelligence services themselves.

As the geopolitical landscape remains volatile, the saga of HEAVYGRAM serves as a somber reminder of the vulnerabilities inherent in our interconnected world. Cybersecurity agencies continue to urge the public to remain vigilant, report suspicious activity to their national authorities, and assume that even the most benign-looking software could be a Trojan horse for those with the intent and resources to weaponize technology against the individual.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button