Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

September 15, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Iranian dissidents, journalists, and activists
Incident: State-sponsored campaign using Telegram-controlled malware for global espionage.
Impact: Loss of confidential communications, real-time audio/visual surveillance, and increased physical safety risks for targeted individuals.
Attacker: Iran’s Ministry of Intelligence and Security (MOIS)
Analysis: The Iranian Ministry of Intelligence and Security (MOIS) is utilizing modular malware known as HEAVYGRAM or CHOSEN BRICK to target high-interest individuals. The attackers employ social engineering to trick victims into installing fake versions of common software, subsequently establishing a C2 channel via Telegram bots. The malware’s ability to access microphones and screens makes it a potent tool for real-time surveillance and intelligence gathering.
Recommendations: Verify the authenticity of all software downloads through official vendor channels.; Implement strict email and messaging filters to block suspicious attachments and social engineering lures.; Monitor system registry keys and network traffic for unauthorized connections to Telegram API endpoints.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *