Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Iranian dissidents, journalists, and activists
Incident: State-sponsored campaign using Telegram-controlled malware for global espionage.
Impact: Loss of confidential communications, real-time audio/visual surveillance, and increased physical safety risks for targeted individuals.
Attacker: Iran’s Ministry of Intelligence and Security (MOIS)
Analysis: The Iranian Ministry of Intelligence and Security (MOIS) is utilizing modular malware known as HEAVYGRAM or CHOSEN BRICK to target high-interest individuals. The attackers employ social engineering to trick victims into installing fake versions of common software, subsequently establishing a C2 channel via Telegram bots. The malware’s ability to access microphones and screens makes it a potent tool for real-time surveillance and intelligence gathering.
Recommendations: Verify the authenticity of all software downloads through official vendor channels.; Implement strict email and messaging filters to block suspicious attachments and social engineering lures.; Monitor system registry keys and network traffic for unauthorized connections to Telegram API endpoints.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source