Select a theme from the list.
Insights

From our experts

Latest
Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersTelegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to Intruders
Security Insight

Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National Borders

Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National Borders
Photo by Ann H on Pexels

Security agencies in the United States, United Kingdom and Netherlands have detailed Windows malware attributed to Iran's intelligence service. Known as HEAVYGRAM or CHOSEN BRICK, the implant uses Telegram-based command channels to steal communications, record audio, capture screenshots and monitor people considered politically sensitive.

News Date: 2026-09-15

A newly detailed cyberespionage campaign shows how familiar messaging and cloud services can be turned into surveillance infrastructure. Security agencies in the United States, United Kingdom and Netherlands say Windows malware known as HEAVYGRAM or CHOSEN BRICK has been used by Iran's Ministry of Intelligence and Security against dissidents, journalists and activists.

Social Engineering Opens the Door

The operation begins with direct contact. Attackers may impersonate a trusted person or technical support representative before sending a file presented as legitimate software or sensitive information. Reported disguises have included Telegram, KeePass, AI applications, antivirus products and even medical scan results.

Opening the file displays a convincing decoy while malware installs in the background. The implant establishes persistence through a Windows registry startup entry and may configure Microsoft Defender exclusions so that selected directories are no longer scanned.

Each compromised computer can communicate with a dedicated Telegram bot. This design allows operators to issue commands and keep activity associated with individual victims separated. The malware can capture screenshots, activate the microphone, collect saved passwords, copy browser-accessible Telegram and WhatsApp information, download additional payloads and delete files. Some versions also support destructive wiping.

Stolen information can be transferred through Telegram and commercial cloud storage services, while newer variants reportedly use proxy infrastructure to obscure communications. This blending of malicious traffic with legitimate platforms can make simple domain blocking impractical.

Protection Requires More Than Indicators

  • Block unapproved applications and executable files delivered through messaging services.
  • Keep Windows, browsers and security tools fully updated.
  • Prevent ordinary users from creating antivirus exclusions.
  • Monitor registry startup locations and unusual microphone access.
  • Investigate unexpected connections to Telegram APIs, proxy networks and cloud storage providers.
  • Provide enhanced protection for journalists, researchers and other high-risk personnel.

In my view, this campaign is especially concerning because the consequences extend beyond conventional data theft. Compromised messages, contacts, screenshots and location clues can expose a victim's professional network and physical routine, potentially creating personal safety risks.

Organizations supporting politically exposed users should assume attackers will switch between corporate and personal devices. Managed endpoints remain important, but secure communication procedures, application control and rapid access to trusted incident response assistance are equally necessary. When cyberespionage is connected to real-world intimidation, endpoint security becomes part of protecting people, not merely protecting information.

Talk to our team →

Latest

Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersSep 16, 2026Ransomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisSep 16, 2026Cisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesSep 16, 2026Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterSep 14, 2026Claude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketSep 14, 2026Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockSep 14, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path