Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
- ID
- 24766
- Status
- summarized
- Published
- 16 Sep 2026, 12:29 AM
- Fetched
- 16 Sep 2026, 1:46 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 16 Sep 2026, 1:47 AM
- Tags
- Audience
- security-practitioners
What happened
A joint advisory from the FBI, NCSC, and AIVD details a Windows malware dubbed HEAVYGRAM/CHOSEN BRICK, attributed to Iran's Ministry of Intelligence and Security, used to spy on dissidents and journalists since at least autumn 2023. The malware is controlled via Telegram and can exfiltrate emails, chats, screenshots, and audio recordings. The FBI released updated technical analysis and new indicators of compromise on September 15, 2026.
Why it matters
This is targeted nation-state espionage against political dissidents and journalists, not a vulnerability in software this audience builds or ships. There is no actionable takeaway for general developers, AI/ML learners, or SaaS founders unless they are building threat-intel tooling or advising at-risk users on OPSEC.
Discussion angle
Only worth mentioning briefly as a reminder that Telegram can be used as a C2 channel for malware — relevant if you are building chat-based tooling or advising users in high-risk environments, but otherwise a skip for this audience.