Iranian Hackers Use Telegram Malware to Spy on Targets
Cybersecurity agencies in the U.S., U.K., and Netherlands have warned about a Windows malware campaign linked to Iran's Ministry of Intelligence and Security (MOIS). Known as HEAVYGRAM by the FBI and CHOSEN BRICK by the U.K. NCSC, the malware uses Telegram as a command-and-control channel to spy on targeted individuals.


The malware can steal emails, chat data and saved passwords, capture screenshots, record microphone audio, and download additional malicious files. Attackers reportedly disguise the malware as legitimate applications such as Telegram, KeePass, Norton Antivirus, Adobe Flash Player and AI-related software, making social engineering a key part of the attack.
The campaign highlights how convincing files and trusted applications can be used to compromise Windows devices. Users and organizations should keep security software updated, avoid opening unexpected files or links, and use advanced antivirus and endpoint protection capable of detecting malware, suspicious behavior and data theft.
NPAV Endpoint Security, help detect fileless malware, block malicious scripts, and protect users from credential-stealing attacks delivered through fake software downloads.