Particle.news

UK, US and Netherlands Attribute Telegram‑Controlled Spyware to Iran's Intelligence Service

Agencies say the Windows malware gives operators access to messages, screenshots and microphones and raises real safety risks for dissidents abroad.

Overview

  • A joint advisory published on September 15 names the spyware family as CHOSEN BRICK (UK) and HEAVYGRAM (US) and attributes the campaign to Iran’s Ministry of Intelligence and Security.
  • The malware runs on Windows, connects each infected PC to a unique Telegram bot for control, and can steal emails, browser chats, screenshots and microphone audio.
  • Operators use tailored social‑engineering on messaging apps to impersonate trusted contacts or tech support and trick targets into opening disguised files such as fake MRI results.
  • Some victims’ personal details have been posted on pro‑Iran leak sites and US authorities seized several such sites in March after previous public warnings about related leaks.
  • The advisory publishes technical indicators and step‑by‑step guidance for defenders and at‑risk individuals to check registry Run keys, block listed domains, enable phishing‑resistant MFA and report suspected compromises.