Close Menu
NCIJ Network NCIJ Network
    What's Hot

    AI and data centers are incredibly unpopular in every poll

    September 16, 2026

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    September 16, 2026

    BIS Study Finds Major Discrepancies in Bitcoin Onchain Metrics

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI and data centers are incredibly unpopular in every poll
    • Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
    • BIS Study Finds Major Discrepancies in Bitcoin Onchain Metrics
    • This Australian cave hid 25,000 years of ritual secrets
    • Congressional Republicans Aim to Shield Fossil Fuel Companies From Climate Lawsuits
    • Lawmaker Opens Probe Into Trump Jr.’s Russian Oligarch-Funded Wedding — ProPublica
    • U.S.-China Summit: Why Trump and Xi Won’t Cooperate on AI Safety
    • Argentina intensifies campaign against Falklands oil companies | Border Disputes News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.

    The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate the microphone to record audio.

    The FBI calls it HEAVYGRAM, and the U.K.’s National Cyber Security Center (NCSC) calls it CHOSEN BRICK.

    The joint advisory was published on September 15 by the NCSC, the FBI, and the Netherlands’ intelligence service, the AIVD. The FBI also released an updated analysis of the malware that expands on a March 2026 alert, the first to describe the campaign, with more technical detail and new indicators of compromise.

    The FBI attributes the malware to Iran’s Ministry of Intelligence and Security (MOIS), the country’s main intelligence agency, and dates the wider campaign to the autumn of 2023. The advisory says CHOSEN BRICK has been used against people in the U.K., the U.S., and the Netherlands, and around the world, since at least 2025.

    The targets are mainly Iranian dissidents, journalists who oppose Iran, activists, and members of groups whose views clash with the government, the agencies say. But the FBI has warned that anyone Iran considers of interest could be a target.

    Cybersecurity

    The agencies say the danger goes beyond stolen data. Screenshots and other collected information can show a target’s contacts, location, and daily routine. The personal details of some victims have appeared on pro-Iranian leak sites, which the advisory says can increase the risk to their safety.

    In March, the U.S. Justice Department seized four such Iranian leak sites, which it said had been used to post stolen data and to call for the killing of dissidents, journalists, and others.

    Iran almost certainly uses this kind of cyber activity to help suppress those it sees as a threat, the agencies say. In some cases, they add, its intelligence services have plotted to kidnap or kill such people abroad.

    How the Attack Works

    The attack begins with a message. The attackers pose as someone the target knows or as tech support for a messaging app, building trust before sending a file that appears to be a legitimate program, the agencies say.

    The attackers often start on a target’s work computer, the agencies say. If that does not succeed, they try to move to a personal device, which company security does not protect.

    Reported disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, and Adobe Flash Player. In some cases, the file was made to look like MRI scan results.

    When the target opens the file, a convincing fake screen appears while the real malware installs in the background. A first stage poses as the app, and a second stage connects the computer to a Telegram bot that the attackers use to control it and collect stolen data. Every version seen so far runs only on Windows.

    To survive a restart, the malware adds itself to a Windows registry “Run” key, so it starts again each time the user logs in. It also tells Microsoft Defender, the built-in antivirus, to skip certain folders so its files are not scanned.

    Each infected computer is given its own Telegram bot, which the agencies say keeps one victim’s activity from mixing with another’s.

    Once running, the malware can be told to do many things: list running programs, take screenshots, turn on the microphone, copy Telegram and WhatsApp data from the browser, steal saved passwords and email addresses, download additional malware, and delete files. At least one version can also wipe the computer, according to the joint advisory.

    The agencies say the malware has not been seen spreading across a network on its own, though it can download more tools. Stolen files leave the computer through the Telegram bot and through cloud storage services such as Vultr and Storj. Newer versions send their Telegram traffic through proxy servers to hide it, the advisory says.

    Signs to Look For

    The advisories list signs that defenders and at-risk users can check for, including:

    • Registry key: a “Run” key entry named SMQDService or winappx, added so the malware starts at login.
    • File path: a folder with an added space, C:Windows SysWOW64, where the malware drops extra files.
    • Network: unexpected connections to otherwise-legitimate services, including api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net.
    • Mutex: name markers the malware sets to avoid running twice, such as ytyjyujyu and noi672pp434awkc12f.

    The FBI’s analysis and the joint advisory contain the full list, including file hashes. The agencies warn that the malware’s file names and folders can change, so these signs should not be treated as the only ones to watch for.

    Cybersecurity

    How to Protect Yourself

    To lower the risk, the agencies recommend that individuals:

    • Do not open files sent through messages or links, and download software only from official websites or app stores.
    • Keep the operating system and all apps up to date, ideally with automatic updates.
    • Run antivirus software and keep it switched on and current.
    • Do not ignore SmartScreen warnings when downloading files.

    They advise network administrators to:

    • Turn on phishing-resistant multi-factor authentication.
    • Use application allowlisting and managed-device controls.
    • Use the scanning and security tools their email provider offers.
    • Monitor computers and network traffic, and search logs for the indicators above.

    Anyone who suspects an infection should check the “Run” key described above, tell their IT support, and report it to their national cyber agency. The advisories do not say whether removing the malware alone clears a compromise.

    When the FBI first warned about the campaign in March, Telegram told TechCrunch that its moderators “routinely remove any accounts found to be involved with malware.” The agencies present their conclusions as assessments rather than as matters settled in court.

    Dissidents hackers Iranian journalists Malware Spy TelegramControlled
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    Politics live: former spy boss says ‘ball was dropped’ on antisemitism; Hastie says One Nation channelling ‘Maga’ | Australian politics

    “We Think the Security Control Is Working” Is No Longer Good Enough

    Western intelligence warns of Iranian cyber threats targeting dissidents | Cybersecurity News

    Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

    What Zero-Day Response Should Be in the Post-Mythos Era

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    AI and data centers are incredibly unpopular in every poll

    September 16, 2026

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    September 16, 2026

    BIS Study Finds Major Discrepancies in Bitcoin Onchain Metrics

    September 16, 2026

    This Australian cave hid 25,000 years of ritual secrets

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    AI and data centers are incredibly unpopular in every poll

    September 16, 2026

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    September 16, 2026

    BIS Study Finds Major Discrepancies in Bitcoin Onchain Metrics

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.