Cybersecurity

International Intelligence Agencies Expose Sophisticated Iranian Malware Campaign Targeting Global Dissidents and Journalists

A coordinated investigation by the United States Federal Bureau of Investigation (FBI), the United Kingdom’s National Cyber Security Center (NCSC), and the Netherlands’ General Intelligence and Security Service (AIVD) has unveiled a persistent and sophisticated cyber-espionage campaign orchestrated by Iranian state actors. The operation, which utilizes specialized Windows-based malware to infiltrate the devices of political dissidents, journalists, and human rights activists, represents a significant escalation in transnational digital surveillance. Known variously as HEAVYGRAM by U.S. authorities and CHOSEN BRICK by their British counterparts, the malicious software is specifically designed to transform a target’s personal or professional workstation into a remote surveillance terminal, enabling real-time monitoring and data exfiltration.

The joint advisory, published on September 15, 2026, serves as the most comprehensive technical assessment to date regarding the digital activities of Iran’s Ministry of Intelligence and Security (MOIS). By linking the malware directly to the MOIS, Western intelligence agencies have underscored a shift in how Tehran conducts its influence operations—moving from traditional espionage to the weaponization of commercial communication platforms to facilitate human rights abuses and the systematic targeting of perceived enemies of the state.

Chronology of the Campaign

The origins of this campaign can be traced back to the autumn of 2023, a period marked by heightened geopolitical tensions and increased Iranian interest in tracking the movements of the diaspora. While early iterations of the malware were relatively rudimentary, subsequent analysis indicates that the actors behind the campaign have continuously refined their tactics, techniques, and procedures (TTPs).

By early 2025, the reach of the campaign had expanded significantly, with confirmed infections reported across the United Kingdom, the Netherlands, and the United States. In March 2026, the FBI issued an initial alert warning of the threat, marking the first time the public was formally notified of the MOIS’s use of Telegram-based Command and Control (C2) infrastructure to manage infected Windows systems. The September 2026 update provides a more granular look at these developments, incorporating new indicators of compromise (IOCs) and detailing how the attackers have successfully evaded detection for nearly three years.

The Anatomy of the Attack: Technical Sophistication

The efficacy of HEAVYGRAM/CHOSEN BRICK lies in its deployment through social engineering rather than purely technical exploits. Attackers typically initiate contact through messaging platforms, often masquerading as trusted associates, colleagues, or technical support representatives. By establishing a veneer of legitimacy, they manipulate the target into downloading a malicious file disguised as a benign application.

See also  AI Agents Compress Exploit Timelines and Shatter Traditional Open Source Security Models
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Among the observed disguises are installers for legitimate software, including the AI-driven video tool Pictory, the popular password manager KeePass, messaging service updates for Telegram, and enterprise tools like Adobe Flash Player. In more aggressive attempts, the malware has been packaged to mimic sensitive documents, such as medical MRI scan results, preying on the victim’s personal urgency to open the file.

Once the file is executed, a two-stage infection process commences. The first stage presents a convincing, non-malicious interface to the user to prevent suspicion, while the second stage silently establishes a connection to a Telegram bot. This bot serves as the central nervous system for the attack, allowing the MOIS operators to issue commands and receive stolen data through the encrypted messaging platform.

The technical capabilities of the malware are extensive:

  • Surveillance: The ability to activate microphones for audio recording and capture continuous screenshots of the user’s desktop.
  • Data Exfiltration: Automated harvesting of emails, web browser credentials, and session data from messaging applications like WhatsApp and Telegram.
  • Persistence: The malware writes itself into the Windows Registry "Run" key, ensuring it executes automatically upon system boot.
  • Evasion: It employs self-exclusion techniques, modifying Microsoft Defender settings to ensure that specific folders—where the malware hides—are excluded from routine security scans.
  • Command Execution: The attackers can remotely download additional malicious payloads, delete critical system files, or, in extreme cases, trigger a full system wipe to cover their tracks.

Strategic Implications and Human Cost

The intelligence community views this campaign not merely as a data theft operation, but as a critical component of Tehran’s broader strategy to suppress dissent. By gaining access to a target’s digital life, the MOIS can map out entire networks of activists, identify their physical locations, and anticipate their movements.

The implications for the victims are severe. Information stolen via HEAVYGRAM has been documented appearing on pro-Iranian leak sites—platforms used to publicly shame and threaten individuals. In March 2026, the U.S. Department of Justice intervened by seizing four such domains, which were found to be hosting stolen private information and inciting violence against journalists and dissidents. The connection between the malware and these public smear campaigns suggests a clear feedback loop: digital infiltration provides the intelligence, and the leak sites provide the platform for psychological intimidation.

Intelligence analysts note that the MOIS does not limit its scope to purely political actors. The advisory warns that any individual deemed of interest by the Iranian government—including academics, dual citizens, and those involved in humanitarian aid—could fall victim to this infrastructure. This trend is consistent with reports of Iranian intelligence operatives attempting to orchestrate kidnappings or extrajudicial actions against dissidents residing in Europe and North America.

See also  Grinex Crypto Exchange Blames "Western Intelligence" for $13.7 Million Hack Amidst Sanctions and Suspected Ties to Illicit Activities
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Official Responses and Mitigation Strategies

Following the publication of the joint advisory, cybersecurity experts have emphasized the importance of a "defense-in-depth" posture. Because the malware relies on human interaction, technical safeguards alone are insufficient.

"The reliance on Telegram as a command-and-control channel is a deliberate choice by these actors to blend their malicious traffic with legitimate data usage," says one industry analyst. While Telegram has previously stated it removes accounts engaged in malicious activity, the modular nature of the MOIS’s infrastructure allows them to rotate bots rapidly, making a total shutdown of the network difficult to achieve.

For organizations and high-risk individuals, the agencies recommend the following defensive measures:

  1. Endpoint Monitoring: Organizations should prioritize the detection of unauthorized changes to Windows Registry keys and audit the execution of suspicious binaries.
  2. Network Segmentation: By restricting administrative access and isolating sensitive workstations, organizations can prevent the lateral movement of malware from a compromised personal device to the corporate network.
  3. Enhanced Verification: Users should exercise extreme caution when downloading files from unsolicited messages, even if the sender appears to be a known contact. Verifying the source of a file via an out-of-band communication channel is essential.
  4. Reporting: Any suspicion of compromise should be immediately reported to national cyber authorities, such as the FBI’s Internet Crime Complaint Center (IC3) in the U.S. or the NCSC in the U.K.

Future Outlook

As the conflict between state-sponsored cyber operations and the privacy of individual activists continues, the HEAVYGRAM campaign serves as a stark reminder of the digital vulnerability of the modern age. The ability of the MOIS to maintain this level of control over a prolonged period demonstrates that sophisticated intelligence agencies are increasingly capable of leveraging common, consumer-grade software to conduct high-stakes espionage.

The ongoing collaboration between the FBI, NCSC, and AIVD is expected to continue as they track the evolution of the malware. While the disclosure of these tactics forces the attackers to burn their current infrastructure, it is anticipated that they will eventually develop new, more stealthy delivery methods. For the global community of journalists and activists, the era of digital safety has passed, replaced by a reality where the integrity of one’s personal device is a fundamental component of physical security. As long as the geopolitical stakes remain high, the battle over the sanctity of these private devices will likely intensify, necessitating even closer cooperation between global law enforcement and the cybersecurity industry to protect those most at risk.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.