UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware can steal messages and emails, capture audio/screens, and leak victims’ personal information online.
How the attack worked
This campaign, linked to Iran's Ministry of Intelligence and Security, relied almost entirely on social engineering rather than technical exploits. Attackers approached targets through everyday messaging platforms including WhatsApp, Telegram, and Instagram. Instead of sending malware immediately, they spent time building rapport with victims, sometimes posing as an individual the target already knew, and other times posing as technical support from the platform itself. Once trust was established, the attacker sent a file disguised as a familiar or useful tool, such as Norton Antivirus, Telegram, the password manager KeePass, or the AI tool Pictory. In some cases, the lure was even more personal: a file presented as MRI scan results.
Why it succeeded
The effectiveness of this campaign came from patience and personalization rather than volume. Because attackers had deep knowledge of their targets, the pretexts felt plausible and the files seemed to come from a trusted source or a legitimate need. High-risk individuals like journalists and activists often receive many messages from unfamiliar contacts, which can make an unusual request blend in. Attackers also tried to steer victims toward opening files on personal devices when work devices had stronger protections, deliberately working around corporate security controls.
What to watch for
- Unsolicited files or software installers sent through WhatsApp, Telegram, or similar apps, even from contacts who seem familiar
- Messages claiming to be "technical support" from a social media platform, especially if they instruct you to install something
- Requests to open sensitive-seeming files, such as medical results, that arrive unexpectedly over chat
- Any suggestion to move a conversation or file exchange to a personal device to "fix" a problem
Building resistance
Organizations supporting high-risk users, including journalists, executives, and communications staff, should reinforce a few habits. Verify identity through a separate channel before opening any file sent via messaging apps, even if the sender appears to be someone known. Treat claims of "platform support" contacted through chat as suspicious, since legitimate support channels rarely operate this way. Establish clear reporting paths for requests to bypass corporate device policies, since this is a deliberate technique attackers use to reach less protected personal devices. Because this spyware can capture messages, audio, screens, and browser data from apps like WhatsApp and Telegram, awareness training should specifically address messaging-based social engineering, not just email phishing, given how central these platforms were to the deception.
Key findings
- Iran-linked attackers used spear-phishing and social engineering to trick targets into downloading malware on Windows devices.
- Attackers contacted victims via messaging and social platforms (including WhatsApp, Telegram, and Instagram) and built rapport before sending files.
- Malicious files were disguised as common tools/apps (Pictory, Norton Antivirus, Telegram, KeePass) and even as MRI scan results.
- Attackers sometimes tried to move the victim to personal devices to bypass corporate security controls.
- The spyware (Chosen Brick / Heavygram) can steal emails/messages, capture screens and audio, and exfiltrate WhatsApp/Telegram data from browsers.
Who’s being targeted
- Commonly targeted roles: Executives, Communications/PR, Journalists/Media, High-risk users, Security awareness training participants who use WhatsApp/Telegram for work.
- Affected industries: Media and journalism, Human rights and advocacy, Non-profits and civil society, Government (dissident and opposition-related targets).
- Attack channels: whatsapp, telegram.
- Impersonated: Technical support from the social media platform, An individual known to the target.
Red flags to watch for
- Unsolicited 'support' outreach through WhatsApp rather than official support channels
- Pressure to install software from a chat attachment/link
- The sender asks to use a personal device to bypass work security
- Unexpected sensitive attachment sent over chat
- File type/name doesn’t match what a medical provider would send
- Sender pushes you to open it on your own/personal device
Frequently asked questions
How did the attackers trick victims into installing spyware?
They built rapport with victims over WhatsApp, Telegram, and Instagram before sending malicious files disguised as legitimate software like Norton Antivirus, Telegram, KeePass, or even MRI scan results.
Who is being targeted by this Iran-linked spyware campaign?
The campaign targets journalists, activists, dissidents, executives, and communications professionals, particularly those who use WhatsApp or Telegram for work.
What can the spyware do once installed?
The spyware can steal emails and messages, capture screens and audio, and exfiltrate WhatsApp and Telegram data from browsers.
Why do attackers ask victims to use personal devices?
Attackers sometimes push victims to open files on personal devices specifically to bypass corporate security controls that would otherwise block the malware.
Read the video transcript
Imagine this WhatsApp: “Hi, this is support from your social media platform, install this tool to fix an issue on your account.” Iran‑linked spyware campaigns do exactly this: they chat on WhatsApp or Telegram, build rapport, then drop a Windows file pretending to be Norton, Telegram, KeePass, Pictory, even MRI scan results. The moment you open it, their spyware can quietly copy your emails, chats, WhatsApp and Telegram data, even record your screen and audio, on both work and personal devices. Here’s the move: if anyone on WhatsApp or Telegram sends you software or “MRI results” and wants you to open it, especially on your personal device, don’t. Stop, verify through a trusted channel, and report it.