UK, US, Dutch agencies warn of Iranian spyware families targeting users via Telegram
The UK NCSC, FBI, and Dutch AIVD jointly published an advisory on 15 September 2026 detailing two Windows spyware families, Chosen Brick and HEAVYGRAM, linked to Iranian intelligence. The malware has been actively deployed since at least 2025, with the broader campaign traced back to autumn 2023. Attackers use WhatsApp and Telegram to impersonate trusted contacts or technical support staff, tricking victims into running a malicious file disguised as a legitimate installer. Once installed, the spyware can capture screenshots, record audio, harvest messaging app data, steal saved passwords, and download additional malware. Agencies noted that unusual Telegram API requests in network logs and unauthorised Windows Defender exclusions in the registry serve as key detection indicators.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in