$ techbeacon▋
Ransomware

Joint UK‑US‑Netherlands Advisory Flags Iranian Windows Malware Targeting Telegram Users

Joint UK‑US‑Netherlands Advisory Flags Iranian Windows Malware Targeting Telegram Users

Security agencies from the United Kingdom, the United States and the Netherlands have released a coordinated warning about a new Windows‑based malware family they have dubbed "Chosen Brick." The advisory, published jointly by the three nations' cyber‑security bodies, says the software is being used to infiltrate the computers of Iranian dissidents, journalists and human‑rights activists who rely on the Telegram messaging platform.

According to the advisory, Chosen Brick is designed to operate stealthily once installed, harvesting credentials, recording keystrokes and transmitting location data back to command‑and‑control servers controlled by actors linked to the Iranian government. The malware leverages familiar Windows system calls, making detection difficult for users who are not running up‑to‑date antivirus solutions.

Telegram, a popular encrypted messaging app in Iran, has long been a target for state surveillance because it offers a relatively open channel for political discussion. By embedding the malicious code in files shared over the app—often disguised as innocuous documents or media—the threat actors can gain persistent access to a victim's device without raising immediate suspicion.

The joint advisory follows a pattern of Tehran‑backed cyber operations that have surfaced over the past several years, including the use of sophisticated spyware such as Pegasus and various custom trojans aimed at silencing opposition voices abroad. While the exact scale of the Chosen Brick campaign remains unclear, the agencies warned that its deployment appears to be part of a broader effort to monitor and intimidate critics of the Iranian regime beyond its borders.

Security experts recommend that users of Windows systems who communicate via Telegram apply the latest security patches, avoid opening unexpected attachments, and employ reputable endpoint protection tools. The advisory also urges organizations that support at‑risk journalists and activists to conduct regular audits of their digital hygiene practices.

The three governments have indicated that they will continue to share intelligence on the malware's evolution and work with international partners to mitigate its impact. As cyber‑espionage tools become increasingly tailored to specific platforms, analysts say that coordinated public warnings like this one are essential to raising awareness and protecting vulnerable communities from state‑sponsored digital harassment.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related