started · updated
Western intelligence warns of Iranian spyware targeting dissidents
Intelligence agencies from the United States, the United Kingdom, and the Netherlands have issued a coordinated warning regarding a cyber espionage campaign attributed to Iran’s Ministry of Intelligence and Security (MOIS). The campaign utilizes a Windows-based spyware family known as ‘CHOSEN BRICK’ (also referred to as HEAVYGRAM) to target dissidents, journalists, and activists.
The malware is reportedly controlled via the Telegram messaging app and is deployed through spear-phishing attacks on platforms like WhatsApp and Telegram. Attackers often impersonate trusted contacts or IT support to trick victims into downloading malicious files disguised as legitimate software, such as Norton Antivirus, KeePass, Adobe Flash Player, or AI tools like RunwayML.
Once installed, the spyware allows actors to steal emails, chat messages, and contact lists, take screenshots, and activate device microphones to record audio. Authorities warned that the stolen data is sometimes leaked on pro-Iranian websites, increasing the physical safety risks for the targeted individuals.
Entities
Chosen Brick · FBI · Federal Bureau of Investigation · General Intelligence and Security Service · Iran · Ministry of Intelligence and Security · National Cyber Security Centre · UK National Cyber Security Centre · United States
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] Malicious files impersonate legitimate software including Norton Antivirus, KeePass, Adobe Flash Player, and RunwayML. uk.pcmag.com
- [● 2 SOURCES] The primary targets of the campaign are Iranian dissidents, journalists, and activists. cybernoz.com · uk.pcmag.com
- [● 2 SOURCES] The spyware, known as CHOSEN BRICK or HEAVYGRAM, is controlled via the Telegram messaging app. cybernoz.com · uk.pcmag.com
- [○ 1 SOURCE] The FBI attributes the malware campaign to Iran’s Ministry of Intelligence and Security (MOIS). cybernoz.com
- [● 2 SOURCES] The spyware can steal emails, chat messages, take screenshots, and activate device microphones. cybernoz.com · uk.pcmag.com
- [● 7 SOURCES] Intelligence agencies from the US, UK, and Netherlands issued a joint advisory regarding Iranian cyber operations. haitigazette.com · stvincenttribune.com · cybernoz.com · barbadosgazette.com · www.noticiasdenavarra.com · +2 more
- [● 3 SOURCES] The malware exclusively targets the Windows operating system. cybernoz.com · www.theregister.com · uk.pcmag.com
- [● 2 SOURCES] Attackers use spear-phishing on WhatsApp and Telegram, impersonating known contacts or IT support. haitigazette.com · uk.pcmag.com