AI Weekly Malaysia

Back to items Summaries

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

ID
24766
Status
summarized
Published
16 Sep 2026, 12:29 AM
Fetched
16 Sep 2026, 1:46 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.0
Created
16 Sep 2026, 1:47 AM
Tags
Audience
security-practitioners

What happened

A joint advisory from the FBI, NCSC, and AIVD details a Windows malware dubbed HEAVYGRAM/CHOSEN BRICK, attributed to Iran's Ministry of Intelligence and Security, used to spy on dissidents and journalists since at least autumn 2023. The malware is controlled via Telegram and can exfiltrate emails, chats, screenshots, and audio recordings. The FBI released updated technical analysis and new indicators of compromise on September 15, 2026.

Why it matters

This is targeted nation-state espionage against political dissidents and journalists, not a vulnerability in software this audience builds or ships. There is no actionable takeaway for general developers, AI/ML learners, or SaaS founders unless they are building threat-intel tooling or advising at-risk users on OPSEC.

Discussion angle

Only worth mentioning briefly as a reminder that Telegram can be used as a C2 channel for malware — relevant if you are building chat-based tooling or advising users in high-risk environments, but otherwise a skip for this audience.

Top