Iranian spies hijack Telegram bots to snoop on dissidents

A joint advisory from three governments exposes Chosen Brick, malware that turns ordinary chat apps into a surveillance pipeline aimed at activists and journalists.

CSBadmin
2 Min Read

A joint advisory from US, UK, and Dutch agencies has exposed a Windows malware family called Chosen Brick, used by Iranian state hackers to surveil dissidents, activists, and journalists.

The campaign starts on familiar ground. Operators build rapport over WhatsApp or Telegram, often posing as acquaintances or platform support staff, then send a weaponised file. Lures have included fake installers for Telegram and KeePass and documents posing as MRI results. When a target opens one, a decoy screen hides the real payload.

Built to survive a reboot and stay quiet

Once running, the malware adds exclusions to Microsoft Defender and writes a registry Run key so it restarts when the user logs in. Every observed infection has hit Windows endpoints, with personal devices treated as fair game alongside corporate ones. That is why the agencies want staff warned at home as well as at work.

Each infected endpoint gets its own Telegram bot for command and control, a design that stops investigators who find one victim from tracing the others. Exfiltration runs over Telegram and cloud storage.

From there operators can log processes, capture screenshots, switch on the microphone, pull chat data out of browsers, steal email, drop extra payloads, or wipe the machine. Harvested material has turned up on pro-Iranian leak sites.

Chosen Brick has stayed on single devices so far. Its ability to fetch further malware means it could spread, though the advisory notes no automated lateral movement exists today.

Anyone who suspects infection should contact their IT provider for an investigation rather than simply reconnecting the device.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.