Global Cybersecurity Alert on Iranian Spyware
Cybersecurity agencies from the United States, United Kingdom, and the Netherlands have issued a comprehensive report revealing a sophisticated Windows-based malware allegedly deployed by Iran’s intelligence agency. This software is designed to infiltrate the devices of dissidents, journalists, and activists worldwide, utilizing the popular messaging app Telegram for control.
The malware, identified as HEAVYGRAM by the FBI and CHOSEN BRICK by the UK’s National Cyber Security Center, is capable of copying emails and chat messages, capturing screenshots, and even recording audio via the device’s microphone.
Details of the Malware Campaign
First announced in March 2026, the joint advisory released on September 15 by NCSC, FBI, and the Netherlands’ intelligence service, AIVD, expands upon earlier findings with additional technical insights and new compromise indicators. The FBI attributes this malware to Iran’s Ministry of Intelligence and Security (MOIS), operating since at least 2023, targeting individuals in the US, UK, and Netherlands.
The malware primarily targets Iranian dissidents, journalists critical of Iran, and other activists whose views conflict with the government. However, the FBI has cautioned that any individuals of interest to Iran may be potential targets, highlighting the global reach of this cyber espionage operation.
Mechanics of the Cyber Attack
The attack typically begins with a deceptive message where attackers impersonate known contacts or technical support, persuading the target to open a seemingly legitimate file. This file, once opened, installs the malware in the background while displaying a fake screen to the user.
The malware, operating exclusively on Windows systems, utilizes a Telegram bot for control and data collection. It positions itself to restart with the system by modifying the Windows registry and instructing Microsoft Defender to bypass certain folders, ensuring its persistence and evasion from standard security scans.
Identification and Protection Measures
Signs of infection include specific registry keys, unexpected network connections to legitimate services, and unique file paths. The advisory outlines these indicators for at-risk users and cybersecurity professionals to detect potential threats.
To mitigate risks, individuals are urged to avoid opening files from unverified sources and maintain updated systems and software. Network administrators are advised to implement robust security measures, including multi-factor authentication and network monitoring tools.
Conclusion and Preventive Actions
The advisory underscores the importance of vigilance and proactive measures in combatting such cyber threats. While Telegram moderators actively remove malicious accounts, users are encouraged to report any suspicious activities to their national cyber agencies. Understanding the implications of this spyware and adopting recommended security practices are crucial steps in safeguarding against such espionage threats.
