VMTech
Discuss a project

Iran-linked Telegram malware targets dissidents on Windows

Iran-linked Telegram malware targets dissidents on Windows

Joint advisory details Telegram-controlled Windows spyware

The FBI, the UK National Cyber Security Centre and the Netherlands' AIVD have published a joint advisory on a Windows malware family used to target Iranian dissidents, journalists, activists and people whose views conflict with the Iranian government. The FBI calls the malware HEAVYGRAM, while the NCSC identifies it as CHOSEN BRICK.

The agencies published the advisory on September 15, alongside an updated FBI analysis that adds technical detail and indicators of compromise to a March 2026 alert. The FBI attributes the activity to Iran's Ministry of Intelligence and Security, or MOIS, and dates the wider campaign to autumn 2023. CHOSEN BRICK has been used against people in the UK, US and Netherlands, as well as elsewhere, since at least 2025.

The advisory describes a risk that extends beyond data theft. Screenshots and other material collected from a device can expose a person's contacts, location and daily routines. It says personal data from some victims has appeared on pro-Iranian leak sites, potentially raising safety risks. In March, the US Justice Department seized four Iranian leak sites it said had posted stolen data and called for the killing of dissidents, journalists and others.

How the malware gains access and persists

Operators begin with direct messages, posing either as someone known to the target or as technical support for a messaging application. After building trust, they send a file presented as legitimate software. Reported lures include Pictory, KeePass, Telegram, RunwayML, Norton Antivirus and Adobe Flash Player; some files were presented as MRI scan results.

When the recipient opens the file, a convincing decoy window is displayed while the malware installs in the background. A first stage impersonates the advertised application, then a second stage connects the computer to a Telegram bot used for commands and data collection. All versions observed so far run on Windows.

For persistence, the malware creates a Windows registry Run key entry so it launches when a user logs in. It also instructs Microsoft Defender to exclude selected folders from scanning. Each compromised computer is assigned a separate Telegram bot, a design the agencies say keeps one victim's activity separate from another's.

Collection capabilities and defender indicators

Once installed, HEAVYGRAM or CHOSEN BRICK can list running programs, take screenshots, activate the microphone, collect browser-held Telegram and WhatsApp data, and steal saved passwords and email addresses. It can download additional malware and delete files. At least one observed version can wipe the computer. The agencies have not observed the malware spreading independently through a network.

Data can be transferred through the Telegram bot and cloud storage services including Vultr and Storj. Newer variants route Telegram traffic through proxy servers. Defenders are advised to investigate a Run-key value named SMQDService or winappx, files under C:\Windows \SysWOW64, and unexpected connections to services such as api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com and lightningproxies.net. Mutex values including ytyjyujyu and noi672pp434awkc12f are further indicators.

The agencies caution that file names and folders can change, so these indicators are not sufficient on their own. Businesses should limit software installation to official sources, maintain updates and active antivirus protection, use phishing-resistant multi-factor authentication, apply allowlisting and managed-device controls, and review endpoint and network logs for the published indicators. A suspected compromise should be escalated to IT support and the relevant national cyber agency.

#cybersecurity#malware#windowssecurity#threatintelligence
Open analytics
On the site 0 views
min read 4 15.09.2026
Instagram

Iran-linked Telegram malware targets dissidents on Windows

Open the post on Instagram ↗