Back to Blog
Nation-State Threats

Iran's MOIS Uses Telegram-Controlled Spyware Against Dissidents

A joint FBI, NCSC, and AIVD advisory details CHOSEN BRICK, Windows spyware that Iran's intelligence service has run through Telegram bots since 2023 to surveil journalists and activists worldwide.

PyramidLedger Research4 min read
Share

Key Takeaways

  • The FBI, UK NCSC, and Dutch AIVD jointly attributed a Windows spyware family — called HEAVYGRAM by the FBI and CHOSEN BRICK by the NCSC — to Iran's Ministry of Intelligence and Security (MOIS).
  • The malware uses a Telegram bot as its command-and-control channel, letting operators issue commands and exfiltrate stolen data through ordinary-looking Telegram API traffic.
  • Targets are Iranian dissidents, journalists, and activists in the UK, US, Netherlands, and elsewhere, reached via spear-phishing on WhatsApp and Telegram using tailored social engineering, including fabricated medical documents as lures.
  • Some victims' stolen personal data has surfaced on pro-Iranian leak sites, turning espionage into a reputational-harm and intimidation tool.

On 15 September 2026, the FBI, the UK's National Cyber Security Centre (NCSC), and the Netherlands' AIVD published a joint advisory attributing a Windows spyware family to Iran's Ministry of Intelligence and Security (MOIS). The FBI designates it HEAVYGRAM; the NCSC calls it CHOSEN BRICK. Both names describe the same campaign, which the FBI dates back to autumn 2023.

A Telegram bot as the command channel

What makes this operation notable isn't the spyware's feature set — it's fairly standard for state-linked implants — but its control channel. After initial infection, a second stage connects the compromised machine to a Telegram bot that operators use both to issue commands and to receive stolen data. Newer variants route this Telegram traffic through proxy infrastructure, which blends malicious C2 calls into traffic that looks like ordinary Telegram API usage — a technique that has become increasingly common precisely because it complicates network-based detection without requiring custom protocol engineering.

Capabilities

  • Copying emails and chat messages
  • Capturing screenshots and activating the microphone for audio recording
  • Listing running programs and extracting Telegram/WhatsApp browser data
  • Harvesting saved passwords and email addresses
  • Downloading additional malware, and in some versions, deleting files or wiping the machine

Who is being targeted, and how

According to the advisory, the targets are mainly Iranian dissidents, journalists critical of Iran, activists, and members of groups whose views conflict with the government — located in the UK, US, Netherlands, and more broadly. The NCSC described the delivery method as tailored spear-phishing over WhatsApp and Telegram: attackers posed as trusted contacts and, in some cases, used fabricated documents — including fake MRI test results — to persuade specific individuals to open the malicious payload. This is social engineering built around a single target's life circumstances, not a mass phishing blast.

The NCSC also noted that some victims' personal details later appeared on pro-Iranian leak sites — meaning the operation's value to MOIS extends beyond intelligence collection into reputational harm and intimidation of people who are often already at personal risk.

Why this matters beyond the immediate targets

Three governments co-signing one advisory on a single spyware family signals sustained, cross-border targeting rather than an isolated incident. For defenders more broadly, the pattern is worth internalizing even outside the activist and journalist community it's aimed at: legitimate consumer platforms (Telegram, WhatsApp) are increasingly used as both the lure and the infrastructure, which means detection has to look past the fact that traffic to api.telegram.org looks routine. Organizations that support at-risk individuals — NGOs, press-freedom bodies, diaspora groups — are the ones most likely to see this specific campaign, and should treat unsolicited documents from known contacts on messaging apps as a credible delivery vector, not just email attachments.

Practical mitigations from the advisory align with general anti-spyware hygiene: verify unexpected files from known contacts through a second channel before opening them, watch for unusual Telegram/API network activity from endpoints that shouldn't be using it, and treat devices belonging to high-risk individuals (journalists, activists) as requiring elevated monitoring rather than standard consumer-grade defenses.

Frequently Asked Questions

What is CHOSEN BRICK/HEAVYGRAM malware?

It's a Windows spyware family, publicly attributed by the FBI, UK NCSC, and Dutch AIVD to Iran's Ministry of Intelligence and Security, that steals emails, chat messages, and screenshots, and can activate a device's microphone. The FBI calls it HEAVYGRAM; the NCSC calls it CHOSEN BRICK.

Why does the malware use Telegram for command-and-control?

A second-stage component connects infected machines to a Telegram bot that operators use to send commands and collect stolen data. Because the traffic goes to Telegram's own API infrastructure, it can blend in with legitimate app usage, and newer variants add proxy servers to further obscure the connection.

Who is being targeted by this campaign?

The advisory says targets are mainly Iranian dissidents, journalists critical of the Iranian government, activists, and members of opposition-aligned groups in the UK, US, Netherlands, and elsewhere, typically reached through tailored spear-phishing on WhatsApp and Telegram.

Sources

  1. 1Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and JournalistsThe Hacker News
  2. 2US, UK, Netherlands warn of Iranian CHOSEN BRICK spyware targeting pressThe Jerusalem Post
Share

Read next