Iranian hackers target dissidents, activists, journalists wordwide with Telegram-linked Chosen Brick spyware
In one case, the attackers even sent fake MRI scan results to trick the victim into downloading the spyware.

Image by Cybernews.
- US, UK, and Dutch agencies warn Iranian-linked hackers are targeting dissidents, activists, and journalists.
- Chosen Brick spyware uses Telegram infrastructure to steal messages, contacts, files, screenshots, and microphone audio.
- Attackers build trust through messaging apps and disguise malware as legitimate files, including fake medical results.
- Authorities urge high-risk people to avoid unsolicited downloads, update software, and use trusted app sources.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Iranian-linked hackers are targeting dissidents, activists, and journalists living in the US, UK, and nations worldwide using a newly exposed strain of malware that uses Telegram infrastructure to secretly monitor its victims, the FBI warns.
Details about the Iranian espionage campaign were released Tuesday in a joint advisory from the FBI’s IC3, the UK’s National Cyber Security Centre (NCSC), and the Netherlands’ General Intelligence and Security Service (AIVD).
The malware, dubbed "Chosen Brick," has been linked to Iranian cyber operations since at least 2025, with the FBI tracking malware from the same family under the name "Heavygram," dating back to 2023.
Chosen Brick enables Iranian state cyber actors to collect information on a target’s contacts, emails, and social media messages, which could enable tracking of their movements, the NCSC warns.
It has been observed exclusively targeting Windows operating systems.
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ says even compromising one person can give an intelligence operator visibility into an entire network around them.
Messages, contacts, and location data can reveal who someone trusts, who they meet with, and which relationships may be worth targeting next.said Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ.
For journalists or activists, that could expose sources and collaborators who never interacted with the attacker at all,
Hackers use Telegram to spy on targets
The attack chain is detailed in accompanying reports also released Tuesday by both the FBI and the NCSC, including technical information about the Chosen Brick malware, indicators of compromise, and security measures for individuals and organisations to protect against an attack.
Although the hackers are using spear phishing to tailor tactics depending on their target and intended outcome, the attacks are said to follow a “core pattern.”
The attacks begin with extensive research and social engineering on a target, with hackers then contacting them through encrypted messaging platforms, such as WhatsApp and Telegram.
The actors have been observed impersonating trusted contacts or support personnel and taking time to build relationships with the target before trying to get them to download and open a malicious file on their device -- disguising the payload so it appears authentic and complements the ruse.
These files have ranged from fake applications that mimic legitimate apps such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, the NCSC said.
In one case, the attackers even sent a file of MRI scan results to lure in the victim.
Attackers have also tried to get the victims to move from protected corporate devices to personal computers, which Costis said is worth paying attention to.
“The advisory says actors have deliberately moved attacks onto personal devices when workplace protections created too much friction. Security teams can’t assume a blocked attempt at work ends the operation,” he explained.
Stealthy and multi-functional malware
Once opened, the malicious payload deploys additional malware that is said to leverage Telegram for command and control (C2) – blending in with legitimate processes, while in reality, supporting a wide range of potential operational outcomes.
Cleverly, investigators found the attackers would connect each victim’s device to “a different Telegram Bot ID unique to them as an Operational Security precaution, preventing cross-contamination between victims.”
Other characteristics showed that once the malware is installed on a Windows computer, Chosen Brick establishes persistence and can survive multiple reboots.
Authorities say Chosen Brick can take screenshots, record microphone audio, steal emails and messaging data, collect files from the infected device, and even download additional malware or wipe/delete data from the device.
The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,said Paul Chichester, National Cyber Security Centre Director of Operations.
Attackers can then exfiltrate stolen information via their Telegram bots and cloud services, with some data already appearing on pro-Iranian leak sites.
The FBI says screenshots and other surveillance can easily expose a victim's contacts, location, and "pattern of life" without their knowledge, creating risks beyond ordinary data theft.
Iran’s history of targeting journalists
Labeled by the UK as transnational repression – a term for when foreign governments target critics and other individuals living outside their nation’s borders. Currently, there are an estimated 10 million Iranians living outside the Middle Eastern nation.
In some cases, the Iranian intelligence services reportedly have plotted to kidnap or conduct lethal operations against individuals abroad who are perceived as enemies of the regime, the advisory states.
It's also not the first time journalists have been targeted by pro-Iranian groups linked to the nation's hard-line government cyber operations.
Last July, several Iranian-born journalists working at the London headquarters of Iran International, one of the nation's only sources of independent news, were targeted by Handala, a state-run group with known connections to the MOIS.
The hackers, using Telegram as their platform, boasted of having hacked the news station while also doxxing the identities of 71,000 individuals, both readers and staff, including several prominent female on-air reporters.
The stolen data allegedly included an abundance of PII and company data, from confidential communications and security details of staff members to bank records, financial contracts, and internal company data.
Handala has become one of the most active cyber actors in the recent Iranian conflict, relentlessly targeting the West.
In the weeks following the start of Operation Fury, the group made waves after leaking the sensitive data of 28 Lockheed Martin engineers allegedly working on military projects in Israel.
Then in May, it leaked the personal information of hundreds of US Navy officers and thousands of US Marines stationed around the Persian Gulf, as well as claiming FBI Director Kash Patel.
Protecting against Chosen Brick
Authorities are urging potential targets to remain cautious about unsolicited communications and downloads, particularly when approached through messaging platforms.
With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.said Paul Chichester, National Cyber Security Centre Director of Operations.
The cyber watchdog agencies also recommend keeping software updated, downloading applications from trusted sources, and using strong authentication protections.
Costis further says organizations supporting high-risk individuals should test these scenarios as connected attack paths.
“Adversarial exposure validation can show where protections break once an attacker changes channels, devices, or identities and keeps pursuing the same target,” he said.
The UK government issued separate guidance on Tuesday for people who believe they may be victims of transnational repression.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.