Iranian Actors Lure Targets via Telegram/WhatsApp

UK NCSC · High sophistication
Last updated September 16, 2026

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results) that secretly install CHOSEN BRICK malware to steal messages, emails, contacts, and other sensitive information.

How the attack worked

According to the UK NCSC advisory, Iranian state-linked cyber actors approached dissidents, activists, and journalists directly through social messaging apps, primarily Telegram and WhatsApp. The actors posed as trusted entities, sometimes claiming to be an individual the target already knew, other times posing as technical support from the messaging platform itself. This initial contact was used to build rapport over time before any malicious content was introduced.

Once trust was established, the actor persuaded the target to download and open a file that looked authentic. Observed lures included installers disguised as well-known software such as Telegram, Norton Antivirus, Adobe Flash Player, KeePass, Pictory, and RunwayML, as well as documents presented as MRI scan results. Opening these files led to the installation of CHOSEN BRICK malware, which uses Telegram for command-and-control and can steal emails, messages, screen captures, contacts, and other sensitive information.

Why it succeeded

The approach worked because it relied on gradual trust-building rather than a single urgent message. By impersonating a known contact or platform support, the actor lowered the target's guard before ever requesting a download. The file types chosen, familiar apps and personal medical documents, were designed to feel routine and non-threatening rather than suspicious.

When a work device blocked delivery, the actor adapted by asking the target to open the file on a personal device instead, bypassing corporate security controls entirely. This flexibility meant a single technical safeguard was not enough to stop the attack chain.

What to watch for

  • Unsolicited chat messages that build rapport before pushing a file download
  • Contacts claiming to be platform

Key findings

  • Actors initiate contact over social messaging platforms (notably Telegram/WhatsApp) while pretending to be trusted entities.
  • They build rapport first, then persuade the target to download and open a file that looks authentic (fake apps or documents).
  • Observed lures included installers disguised as common software (e.g., Telegram, antivirus, KeePass) and files that looked like “MRI scan results.”
  • If delivery to a work device is blocked, the actor may ask the target to open the file on a personal device to bypass corporate controls.
  • CHOSEN BRICK uses Telegram for command-and-control and can steal emails, messages, screen captures, and other sensitive data; some victim data later appeared on pro-Iranian leak sites.
  • The advisory highlights specific domains that may appear in logs unexpectedly (e.g., api[.]telegram[.]org, vultrobjects[.]com, storjshare[.]io).

Who’s being targeted

  • Commonly targeted roles: All staff (with emphasis on at-risk individuals), Journalists / newsroom teams, Executive leadership, Communications and public-facing staff, NGO / human rights organization staff, IT helpdesk and security teams (for reporting and response).
  • Affected industries: Media and journalism, Human rights and civil society organizations (NGOs), Government / public sector (dissident monitoring), Technology platforms (messaging apps used as delivery channels).
  • Attack channels: telegram, whatsapp.
  • Impersonated: Telegram technical support, Someone previously known to the target, Trusted entity sharing a recommended tool/application.

Red flags to watch for

  • “Support” contacts you first via chat and pushes a file download
  • Being asked to install software sent directly in a message instead of using an official app store/site
  • Pressure to switch from work device controls by moving to a personal device
  • Unexpected sensitive attachment delivered via chat
  • File tries to appear legitimate while doing something in the background
  • Sender identity can’t be verified through a known, separate channel
  • Software installer delivered via direct message instead of official source
  • The app name is well-known, but the download method is unusual
  • Asked to move the process to a personal device if a work device blocks it
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do Iranian cyber actors initiate contact with targets?

They reach out over social messaging platforms like Telegram and WhatsApp, pretending to be trusted entities such as technical support or someone the target already knows.

What kind of files are used to deliver the malware?

Lures include installers disguised as common software like Telegram, Norton Antivirus, Adobe Flash Player, and KeePass, as well as documents that appear to be MRI scan results.

What happens if a work device blocks the malicious file?

The actor may ask the target to open the file on a personal device instead, which helps evade corporate security controls.

What does the malware do once installed?

CHOSEN BRICK uses Telegram for command-and-control and can steal emails, messages, screen captures, and other sensitive data, some of which has later appeared on pro-Iranian leak sites.

Read the video transcript

Imagine this: you’re on Telegram, and “Telegram Support” suddenly messages you about a problem with your account. This is how CHOSEN BRICK malware lands: they build friendly chat on Telegram or WhatsApp, then send a fake app or document, like a Telegram installer, antivirus, KeePass, or even bogus MRI scan results, for you to open. Once you run it, CHOSEN BRICK quietly talks back over api.telegram.org and similar domains, grabbing your messages, emails, contacts, even screenshots, and some of that data has shown up on pro-Iranian leak sites. If anyone on chat, even “support” or a known name, sends you software or a document to install, don’t open it. Go to the official app store or vendor site yourself, and report it to security.

Similar attacks

Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations,…

September 15, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026