HackMyIP
← Back to News
2026-09-15 The Hacker News

Iranian MOIS Deploys HEAVYGRAM Malware to Spy on Dissidents via Telegram

MalwareAPTPrivacy

A joint advisory from the FBI, the U.K.'s National Cyber Security Centre (NCSC), and the Netherlands' AIVD has exposed a Windows malware strain dubbed HEAVYGRAM (also tracked as CHOSEN BRICK by the NCSC) that Iran's Ministry of Intelligence and Security (MOIS) has used since at least 2025 to surveil dissidents, journalists, and activists across the U.S., U.K., Netherlands, and beyond. Published on September 15, 2026, and expanding on an earlier March 2026 FBI alert, the advisory warns that the malware's capabilities extend far beyond ordinary spyware: it exfiltrates emails and chat messages, captures screenshots, and surreptitiously activates the host machine's microphone to record ambient audio. The agencies stress that stolen personal data from some victims has already surfaced on pro-Iranian leak sites—four of which the U.S. Department of Justice seized in March 2026—and that Iran has in past cases plotted kidnappings or assassinations of targets living abroad.

The attack chain is a textbook example of social engineering paired with a multi-stage dropper. Operators typically begin on a target's workstation, posing as a trusted contact or as tech support for a messaging platform to deliver a trojanized file disguised as legitimate software—reported lures include the AI video app Pictory, the KeePass password manager, RunwayML, Norton Antivirus, Adobe Flash Player, Telegram itself, and even fake MRI scan results. When launched, the file displays a convincing decoy interface while a first-stage payload installs in the background; a second-stage loader then beacons out to an attacker-controlled Telegram bot to receive commands and transmit harvested data, leveraging the platform's API for covert command-and-control. Because much of the activity pivots from corporate devices to unprotected personal hardware, standard enterprise endpoint controls often fail to catch the lateral move.

For individuals who suspect exposure—particularly Iranian-affiliated journalists, activists, and human-rights workers—the advisory recommends verifying whether credentials or personal data have appeared in known collections using an email breach checker, hardening device hygiene by scanning for unexpected open services with a port scanner, and running a comprehensive privacy checkup to surface leaking browser metadata that could aid fingerprinting. Security teams should also incorporate the new indicators of compromise from the FBI update into EDR rules, block Telegram-based C2 callbacks at the network egress where possible, and brief high-risk users on the lure tradecraft. The advisory's core message is blunt: anyone Iran deems "of interest" is a potential target, and defenders—whether journalists, NGOs, or enterprises—should treat HEAVYGRAM as an active, ongoing espionage threat rather than a historical one.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Browser Fingerprint →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →