Iran-Linked Hackers target Windows Machines through WhatsApp and Telegram

An Iranian hacking group has reportedly launched a new spyware campaign targeting Windows users through popular messaging platforms such as WhatsApp and Telegram. The campaign comes amid heightened geopolitical tensions involving Iran and the United States, raising concerns about the growing use of cyber operations for surveillance and intelligence gathering, particularly in the west.

The malware used in the campaign has been identified as Chosen Brick, a spyware tool reportedly developed by the Iranian hacking group Handala Hack. The group has previously been associated with cyber-espionage activities and is also suspected of being behind the HeavyGram surveillance backdoor campaign.

What makes the latest campaign particularly concerning is the range of individuals and organizations reportedly being targeted. While political figures, journalists, and other high-profile individuals appear to be among those of interest, the campaign has allegedly extended its reach to government and intelligence organizations in several countries.

Reported targets include individuals and entities associated with the Federal Bureau of Investigation (FBI) in the United States, the UK National Cyber Security Centre (NCSC), and the Netherlands General Intelligence and Security Service. The full extent of the campaign remains unclear, however, and Cybersecurity researchers are still working to determine the complete list of victims and the potential scope of the intrusion.

The use of messaging applications as a delivery mechanism is significant because platforms such as WhatsApp and Telegram are widely used for personal, professional, and official communication. Attackers can potentially exploit users’ trust in messages received through these platforms by disguising malicious files or links as legitimate documents, images, or other content. Once a victim interacts with the malicious payload, the malware may gain access to the Windows system and begin collecting information.

Spyware campaigns of this nature can provide attackers with valuable intelligence, including information about a target’s online activities, communications, files, and other system data, depending on the malware’s capabilities and the permissions it obtains. Such operations can therefore pose a significant risk to journalists, government officials, researchers, and organizations handling sensitive information.

The alleged involvement of Handala Hack also highlights the continuing evolution of Iran-linked cyber-espionage operations. Groups associated with state-sponsored or politically motivated hacking have increasingly relied on social engineering and trusted communication channels to reach potential victims, rather than relying solely on conventional network attacks.

For Windows users, the campaign serves as another reminder of the importance of treating unexpected messages and attachments with caution, even when they arrive through familiar messaging services. Users should avoid opening suspicious files or clicking unknown links, keep operating systems and security software updated, and use additional verification when receiving unexpected documents from contacts.

At this stage, the full victim count and overall impact of the Chosen Brick campaign remain uncertain. As researchers continue investigating the operation, additional information about its targets, infection methods, and capabilities could emerge.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display