The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity agencies from the U.S., U.K., and the Netherlands issued a joint advisory on September 15 about Iranian state-sponsored malware used to spy on dissidents, journalists, and activists.
- The malware, called HEAVYGRAM by the FBI and CHOSEN BRICK by the U.K.'s NCSC, is controlled through the Telegram messaging app and can steal emails, take screenshots, record audio, and steal saved passwords.
- The FBI attributes the malware to Iran's Ministry of Intelligence and Security, with the campaign running since at least 2023 against targets in the U.K., U.S., Netherlands, and worldwide.
- The attackers typically pose as a trusted contact or tech support and trick targets into opening disguised files such as fake copies of KeePass, Norton Antivirus, or Telegram itself; every version seen so far runs only on Windows.
- The danger extends beyond data theft, as stolen information has appeared on pro-Iranian leak sites, raising physical safety risks for victims.
What to watch next
- Further takedown actions or sanctions following the U.S. Justice Department's March seizure of four Iranian leak sites
- Telegram's response and any removal of attacker-controlled bot accounts
- New indicators of compromise as the FBI updates its technical analysis
Coverage1
1 report
English national1
All filed from India
Named United States · United Kingdom · Netherlands · Iran · Telegram · AIVD · CHOSEN BRICK · Department of Justice · Federal Bureau of Investigation · HEAVYGRAM · Ministry of Intelligence and Security · National Cyber Security Center
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
