Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Iran-Linked Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity and intelligence agencies from the United Kingdom, United States and Netherlands have exposed an Iranian state-linked cyber-espionage campaign using sophisticated Windows malware to monitor dissidents, activists and journalists around the world.

The malware, tracked as CHOSEN BRICK by the UK's National Cyber Security Centre (NCSC) and HEAVYGRAM by the FBI, uses Telegram infrastructure for command-and-control (C2) communications.

Once installed, the spyware can steal emails and messaging data, capture screenshots, record microphone audio, collect system information and download additional malware.

The FBI attributes the operation to cyber actors working on behalf of Iran's Ministry of Intelligence and Security (MOIS). The agency says variants of the malware have been deployed against Windows systems since at least the autumn of 2023, while the joint advisory documents CHOSEN BRICK activity against individuals around the world since at least 2025.

Dissidents, Activists and Journalists Targeted

The operation is highly targeted rather than a broad malware-distribution campaign.

Victims have included:

  • Iranian dissidents
  • Journalists critical of Iran
  • Political activists
  • Opposition groups
  • Individuals associated with organizations whose views conflict with Iranian government narratives
  • Other people considered of intelligence interest by Iranian authorities

Cases have been identified in the United Kingdom, United States and Netherlands, as well as other countries.

The NCSC warns that information collected through the malware could allow operators to understand a victim's contacts, communications and potentially their movements.

In some previous cases, personal information belonging to victims subsequently appeared on pro-Iranian leak websites, potentially creating risks extending beyond the original digital compromise.

Attackers Build Trust Before Delivering Malware

CHOSEN BRICK campaigns rely heavily on social engineering and spear-phishing.

Rather than immediately sending an obviously suspicious attachment, attackers may spend time communicating with their target through messaging applications such as WhatsApp and Telegram.

Operators have impersonated people already known to the victim or posed as technical support representatives.

After establishing trust, the attacker persuades the victim to download and execute a malicious file.

The operation has used malware disguised as legitimate software and content, including:

  • Telegram
  • KeePass
  • Norton Antivirus
  • Pictory
  • RunwayML
  • Adobe Flash Player
  • Medical documents
  • Fake MRI scan results

The unusual use of fabricated MRI results demonstrates the level of personalization involved in some attacks.

How the CHOSEN BRICK Attack Works

A typical infection can be summarized as:

Target identified

Attacker researches victim

Contact established through Telegram or WhatsApp

Attacker impersonates trusted person or support service

Trust established through conversation

Malicious file disguised as legitimate content

Victim executes file on Windows computer

CHOSEN BRICK installed

Malware establishes persistence

Telegram-based C2 communication established

Screenshots, messages, files and other intelligence collected

The use of legitimate messaging infrastructure for command-and-control can make malicious communications more difficult to distinguish from ordinary network traffic.

Telegram Becomes the Command-and-Control Channel

One of CHOSEN BRICK's most notable characteristics is its use of Telegram bots as command-and-control infrastructure.

After infection, the malware communicates with Telegram-controlled bots that allow the operators to interact with compromised systems and retrieve collected information.

The FBI says the second stage of malware observed in the campaign connected infected computers to Telegram C2 bots, providing remote access and allowing operators to exfiltrate screenshots and files.

According to the joint advisory, individual infected devices can be associated with separate Telegram bots.

Using a widely used legitimate platform for C2 communication offers attackers an important advantage: defenders cannot simply assume that every connection to Telegram is malicious.

What CHOSEN BRICK Can Steal

The spyware provides operators with extensive surveillance capabilities.

Reported functions include:

Capability Potential Impact
Screenshot capture Monitors activity displayed on the victim's screen
Microphone recording Captures conversations around the computer
Email collection Exposes private communications
Messaging-data collection Provides access to social and messaging information
System reconnaissance Identifies processes and system configuration
File theft Exfiltrates documents and other information
Additional malware download Expands attacker capabilities
File deletion Removes information from compromised systems
Remote command execution Allows further attacker-controlled actions

The malware has also been observed collecting information associated with WhatsApp and Telegram sessions available through browsers.

Screen capture is particularly valuable in espionage operations because attackers can collect information displayed by applications even when directly extracting the underlying application data is difficult.

Malware Can Activate the Microphone

CHOSEN BRICK's surveillance capabilities extend beyond files and messages.

The malware can activate the compromised computer's microphone and record audio, potentially allowing operators to monitor conversations occurring near the device.

Earlier FBI analysis also identified malware functionality capable of recording screen and audio activity while a Zoom session was active.

Combined with screenshots, communications theft and file collection, this gives operators a detailed picture of a target's professional and personal activity.

Why Telegram-Based C2 Matters

Attackers increasingly abuse legitimate cloud and communication services for malware command-and-control.

From a defender's perspective:

Traditional C2

Compromised PC → suspicious attacker domain → C2 server

can be relatively straightforward to identify when the destination has no legitimate business purpose.

Telegram-based communication looks more like:

Compromised PC → Telegram infrastructure → attacker-controlled bot

Blocking Telegram entirely may not be practical for organizations or individuals that legitimately use the service.

Detection therefore needs to incorporate endpoint behavior, process relationships and network context, rather than relying exclusively on domain reputation.

How Defenders Can Detect Potential Compromise

Organizations supporting journalists, activists or other high-risk individuals should pay particular attention to suspicious activity originating from personal Windows devices.

Useful areas for investigation include:

  • Unexpected executables downloaded through messaging applications
  • Programs launched from Downloads or temporary directories
  • Unusual persistence mechanisms
  • Suspicious outbound Telegram communications
  • Unexpected screenshot or audio-recording activity
  • Unknown processes accessing browser data
  • Newly created scheduled tasks
  • Suspicious PowerShell or command-shell activity
  • Unexpected file collection or archive creation
  • Security warnings generated by Microsoft Defender or SmartScreen
  • Processes attempting to access microphone resources without a legitimate reason

The joint advisory provides additional technical indicators and MITRE ATT&CK mappings that defenders can use when investigating suspected infections.

How High-Risk Users Can Protect Themselves

The agencies recommend that individuals who may be targeted remain particularly cautious when receiving files through messaging platforms.

Users should:

  • Avoid opening unexpected files received through Telegram, WhatsApp or other messaging applications.
  • Independently verify the identity of anyone sending unusual software or documents.
  • Download applications directly from official websites or trusted application stores.
  • Keep Windows and installed applications fully updated.
  • Keep antivirus and endpoint protection enabled and updated.
  • Pay attention to Microsoft SmartScreen and security warnings.
  • Avoid disabling security controls simply because someone claiming to be technical support asks them to.
  • Be suspicious when trusted contacts unexpectedly ask them to install software.
  • Report suspected compromise quickly so devices can be investigated before evidence is lost.

High-risk users should also remember that a compromised contact account can make a malicious message appear to come from someone they genuinely know.

A Cyberattack With Potential Real-World Consequences

CHOSEN BRICK is more than conventional information-stealing malware.

The information it collects—contacts, messages, emails, screenshots and potentially location-related details—can provide intelligence about a victim's relationships and activities.

The NCSC specifically warns that information obtained through CHOSEN BRICK could help operators track targets' movements. It also reports that personal details belonging to some previous victims have subsequently appeared on pro-Iranian leak sites.

The UK, U.S. and Dutch agencies therefore characterize the malware as part of a broader Iranian state-linked surveillance operation against individuals viewed as threats to the Iranian government. Iran's embassy in London did not respond to Reuters' request for comment on the allegations.

Security Takeaway

The CHOSEN BRICK campaign demonstrates that sophisticated cyber-espionage does not always begin with a zero-day vulnerability.

In this operation, trust is the initial access vector.

Attackers research their targets, establish relationships through familiar messaging applications and tailor malicious files to subjects likely to interest individual victims.

Once that social-engineering barrier is crossed, Telegram itself becomes part of the malware's command-and-control architecture, allowing operators to remotely collect messages, emails, screenshots, files and audio from compromised Windows computers.

For journalists, activists, dissidents and organizations supporting high-risk individuals, the campaign reinforces the importance of treating unexpected software and attachments as potentially hostile—even when they arrive through a familiar platform or apparently trusted contact.

SEO Meta Description:
Iran-linked hackers are using CHOSEN BRICK, also tracked as HEAVYGRAM, to spy on dissidents and journalists through Telegram-controlled Windows malware that steals messages, screenshots, files and audio.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical Malware

Russian State-Sponsored Hackers Used Claude to Rebuild Malware After Detection

A Russian state-linked cyber-espionage operation has used Anthropic's Claude AI to create an automated malware-evasion workflow capable of detecting when its malicious tools were identified by security products and then modifying and rebuilding those tools to bypass the detections.

critical Malware

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Threat actors are exploiting vulnerabilities in Cisco Secure Firewall Management Center (FMC) to gain access to enterprise environments, steal credentials and ultimately deploy Qilin ransomware, turning vulnerable security infrastructure into an entry point for broader network compromise.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.