Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram
Iranian cyber actors are using a malware family known as HEAVYGRAM, also tracked as CHOSEN 2026-9-18 08:46:34 Author: thecyberexpress.com(查看原文) 阅读量:6 收藏

Iranian cyber actors are using a malware family known as HEAVYGRAM, also tracked as CHOSEN BRICK, to target dissidents, journalists, and opposition groups worldwide, according to a recent FBI FLASH report and a joint advisory from the UK National Cyber Security Centre (NCSC), the US FBI, and the Netherlands’ General Intelligence and Security Service (AIVD).

The FBI assesses that the malware is deployed on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS) to collect intelligence, conduct data leaks, and cause reputational harm to targets. The joint advisory adds that Iran almost certainly uses cyber activity to support repression of individuals seen as threats to the regime.

Who Is Being Targeted by Iranian Cyber Actors

The victim profile includes Iranian dissidents, journalists opposed to Iran, members of organizations with views countering Government of Iran narratives, and other individuals the Iranian government perceives as threats.

The joint advisory notes that CHOSEN BRICK has been used against individuals in the UK, US, and Netherlands since at least 2025, and that personal details of some victims have appeared on pro-Iranian leak sites, increasing risks to their personal safety.

In some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals abroad who are seen as enemies of the regime.

Social Engineering and Delivery

Iranian cyber actors rely heavily on social engineering to deliver their malware. Actors communicate with targets through platforms such as Telegram, WhatsApp, and Instagram, often posing as individuals known to the target or as technical support from the messaging platform.

The joint advisory notes that actors research targets in advance to appear credible, and often initiate contact through a target’s work device before shifting to personal devices if the initial delivery attempt fails or risks detection. Victims are persuaded to download files disguised as legitimate applications, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, or files appearing to be MRI scan results.

The FBI notes that some victims downloaded AnyDesk and provided access strings, while others downloaded malware masquerading as a program installer. The malware targets only the Windows operating system.

Persistence and Telegram Command and Control

Once installed, the malware achieves persistence by adding registry keys, most often within the Run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, so it runs automatically at user login. It also adds exclusions to Microsoft Defender antivirus to evade detection. The malware then connects to Telegram command-and-control infrastructure, with each victim device linked to a unique Telegram Bot ID to prevent cross-contamination between victims.

Through Telegram, the malware can enumerate running processes and system information, capture screen content, enable the microphone to record audio, copy Telegram and WhatsApp data from browsers, download additional files, delete files, steal email content, and wipe the computer system. Files and data are exfiltrated through the Telegram bot and cloud object stores such as VultrObjects and StorjShare. Recent variants use HTTPS/SOCKS5 proxies to obscure the use of Telegram bots.

FBI Recommendations

The FBI recommends caution regarding communications from unknown individuals, keeping devices updated, downloading software only from trusted sources, enabling antivirus software, using strong unique passwords with multi-factor authentication, and reporting suspicious messages.

The NCSC, FBI, and AIVD jointly recommend phishing-resistant multi-factor authentication, application allowlisting, email scanning security features, and endpoint and network monitoring.

Organizations concerned about a potential HEAVYGRAM or CHOSEN BRICK infection are advised to contact their IT providers and check both corporate and personal devices, since the actors also target individuals outside their workplace systems.


文章来源: https://thecyberexpress.com/iranian-cyber-actors-deploy-malware/
如有侵权请联系:admin#unsafe.sh