Iranian State Malware Uses Telegram to Spy on Dissidents and Journalists
Iran's MOIS deployed the HEAVYGRAM/CHOSEN BRICK malware to target dissidents, journalists, and activists by leveraging Telegram as a covert command-and-control channel — a technique designed to blend malicious traffic with legitimate app usage. The malware's capabilities — data theft, screenshots, and audio recording — demonstrate how state-sponsored actors prioritize persistent surveillance over financial gain. Victims' stolen data was then published on pro-Iranian leak sites, compounding physical safety risks beyond the digital breach. This case underscores that high-risk individuals such as journalists and activists face nation-state-level threats and require tailored security guidance beyond standard enterprise controls. Relying on popular consumer apps like Telegram does not guarantee safety, as adversaries can weaponize them as infrastructure.
Tactical Insight
Immediate actions
- Audit and restrict which messaging and cloud applications are permitted on devices used by at-risk individuals, blocking unauthorized Telegram bot traffic at the network level.
- Deploy endpoint detection and response (EDR) tools capable of identifying suspicious process behaviors such as audio capture, screenshot automation, and unauthorized data exfiltration.
- Brief journalists, activists, and dissidents on targeted malware threats and provide them with hardened, dedicated devices for sensitive communications.
Long-term improvements
- Establish a dedicated security assistance program for high-risk individuals (journalists, NGOs, activists) that includes regular threat briefings and device hygiene reviews.
- Implement application allowlisting on endpoints to prevent unauthorized executables — including malware delivered via social engineering — from running.
- Enforce network segmentation so that compromised endpoints cannot freely exfiltrate data or reach external C2 infrastructure.
Detection measures
- Monitor outbound network traffic for anomalous connections to Telegram Bot API endpoints or unexpected cloud services that could indicate C2 activity.
- Enable centralized logging of process creation, microphone/camera access events, and screenshot APIs to detect malware behavioral patterns early.
- Subscribe to threat intelligence feeds covering state-sponsored Iranian threat actors (e.g., MOIS-affiliated groups) to receive timely indicators of compromise (IoCs).