# Iran-linked CHOSEN BRICK spyware lets Tehran track dissidents through fake contacts and Telegram bots

*Tuesday, September 15, 2026 at 6:07 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-15T18:07:27.453Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/17926.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: British, U.S. and Dutch agencies say an Iranian state-backed group is using spyware dubbed CHOSEN BRICK to target exiles, activists and journalists worldwide, impersonating trusted contacts and abusing Telegram bots to steal messages, contacts and files, capture screens, track movements and turn microphones into listening devices.

An Iranian state-backed hacking team is accused of running a surveillance campaign that reaches deep into the phones and laptops of exiles, activists and journalists who rely on digital tools for basic safety.

On 15 September, British intelligence said Iranian government hackers have been targeting dissidents, human rights defenders and media figures around the world with spyware known as “CHOSEN BRICK.” A joint advisory from agencies in the U.K., U.S. and Netherlands links the activity to Iran and describes a toolkit designed to strip away that sense of privacy.

According to the advisory, the operators pose as trusted contacts — colleagues, acquaintances or potential employers — and send booby‑trapped documents. Once the malware is installed, CHOSEN BRICK gives the attackers wide access: stealing messages and contact lists, taking covert screenshots, tracking movements, recording audio through the microphone and pulling stored files.

A related technical report describes HEAVYGRAM, also tracked as CHOSEN BRICK, which uses Telegram bots for command‑and‑control. In practice, that means compromised devices can be managed and data can be exfiltrated via instructions sent over Telegram, the same platform many dissidents use to organize and communicate.

For the people on the receiving end, this isn’t an abstract cyber risk. An activist who assumes a secure messaging app shields them from their home government may in fact be carrying a state‑controlled listening device. Journalists could see their sources exposed, notes copied and movements logged.

The wider impact goes beyond individuals. If a few key devices are compromised, entire networks of contacts can be mapped and disrupted. Opposition coordination, sanctions‑related investigations and outreach to international organizations can all be monitored in near real time. The digital channels that helped Iranian protesters and exiles stay connected are being turned back against them.

The campaign shows how Iran is adding cyber operations to its existing mix of missiles, drones and proxy forces. Western intelligence services have long warned about Iranian activity against infrastructure and companies; this case highlights how the same apparatus is used to monitor political enemies via global platforms.

For technology firms, the advisory is a warning that messaging apps and file‑sharing tools can be turned into parts of a state surveillance system if they aren’t watching closely for abuse. Governments hosting Iranian dissidents also have to ask whether their cybersecurity support is keeping up with the threat.

Key signals now will be whether more victims in Europe, the Middle East and North America come forward, how Telegram and other platforms respond to being named, and whether states move to sanction specific Iranian cyber units. The real measure of impact will be whether at‑risk communities can keep using digital tools without feeling that every conversation is taking place under an unseen microphone.
