Protect.Computer
NEWS

Iran's MOIS Uses Telegram-Controlled Malware to Spy on Dissidents

· 2 min read · Got hacked Privacy tracking
Iran's MOIS Uses Telegram-Controlled Malware to Spy on Dissidents

The FBI, the UK’s National Cyber Security Centre, and the Netherlands’ AIVD intelligence service have published a joint advisory detailing a Windows malware that Iran’s Ministry of Intelligence and Security has been using since at least 2023 to monitor dissidents, journalists who cover Iran, and activists whose views conflict with the Iranian government. The FBI calls the malware HEAVYGRAM; the NCSC calls it CHOSEN BRICK.

The malware is controlled entirely through Telegram bots. Each infected machine is assigned its own dedicated bot, keeping one victim’s activity separate from another’s. Once running, the malware can take screenshots, activate the microphone, copy Telegram and WhatsApp data from the browser, steal saved passwords and email addresses, download additional tools, and — in at least one version — wipe the computer entirely. It persists across restarts by adding itself to a Windows registry Run key, and it tells Microsoft Defender to skip the folders where its files live. Attackers most often reach targets by posing as someone known to them or as tech support, then delivering a file disguised as a legitimate program. Confirmed disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player, and fake MRI scan results. The joint advisory notes that some victims’ personal details — collected data about contacts, location, and daily routines — have since appeared on pro-Iranian leak sites, which the agencies say can expose victims to physical harm. Earlier in 2026, the U.S. Justice Department seized four such Iranian leak sites.

The agencies warn that the danger is not limited to prominent dissidents: anyone Iran considers of interest could be a target, including people in the UK, the United States, and the Netherlands.

How to check if you’re affected

Affected devices are any Windows computers belonging to journalists, activists, researchers, or others who cover Iran or have contact with the Iranian diaspora. To check for infection, open the Windows Registry Editor (regedit) and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run — any entry with an unexpected file path, especially pointing to AppData or Temp folders, warrants investigation. The joint advisory published by the NCSC and the FBI lists full indicators of compromise including file hashes, Telegram C2 patterns, and cloud-storage upload endpoints; check those against your endpoint detection logs.

Sources

Related reading