Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI says actors working on behalf of Iran’s Ministry of Intelligence and Security (MOIS) used tailored lures to infect Windows computers with malware that can communicate through Telegram bots. The campaign, which the FBI says dates back to fall 2023, targeted Iranian dissidents, journalists opposed to Iran, activists and others viewed as threats to the Iranian government. The key risk is not simply receiving a Telegram message: it is being persuaded to open a convincing file that installs malware.

How does the FBI say the Telegram malware campaign works?

In a FLASH dated March 20, 2026, the FBI described a multi-stage campaign. Its assessment attributes the activity to actors acting on behalf of MOIS; that is the FBI’s attribution, not an independently established finding in this article. The FBI says versions of the malware infected Windows systems dating back to fall 2023.

  1. Build trust. The attacker approaches a target with a tailored message and a file or program that appears relevant or familiar.
  2. Get the file opened. The lure may masquerade as software or a service, with examples including Pictory, KeePass and Telegram-themed programs.
  3. Install additional components. The FBI describes a staged payload: an initial component presents as a familiar program or service, while a later implant provides persistent access.
  4. Collect information and communicate remotely. The later implant can connect to Telegram bots, which the FBI says can enable remote access and theft of screenshots or files.

Telegram’s role here is infrastructure used by malware after infection. The warning does not mean that an ordinary Telegram conversation, by itself, infects a device, or that Telegram has been shown to be compromised.

The FBI says the campaign resulted in intelligence collection, data leaks and reputational harm. It also says Handala Hack claimed responsibility for a July 2025 hack-and-leak operation. The FBI assesses that some information posted by the entity came from malware used in its ongoing campaign, and links Handala Hack to Homeland Justice, which the agency also assesses is operated by Iran MOIS cyber actors. These are FBI assessments; the agency did not verify every claim made by Handala Hack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How is the later CHOSEN BRICK warning related?

A joint advisory published on September 15, 2026, by the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD describes a malware family called CHOSEN BRICK. It is relevant context because it also involves targeted social engineering, Windows infections and Telegram infrastructure. The available reports do not establish that CHOSEN BRICK is another name for the malware in the FBI’s March FLASH, or that the two reports describe identical samples or operations.

Point of comparison FBI FLASH Joint CHOSEN BRICK advisory
Publication and period described March 20, 2026; the FBI says malware versions infected Windows systems dating back to fall 2023. September 15, 2026; the NCSC says CHOSEN BRICK targeted individuals from at least 2025.
Named malware Describes a Telegram command-and-control campaign and associated samples; the FBI’s March 20, 2026, FLASH does not give a family name for these samples. Names the malware family CHOSEN BRICK.
Targets and geography People the FBI says were viewed as threats to the Iranian government, including dissidents, journalists opposed to Iran and opposition groups. Individuals including dissidents, activists and journalists in the UK, US and Netherlands.
Delivery and lures Multi-stage Windows payloads disguised as familiar programs or services; examples include Pictory, KeePass and Telegram-themed programs. Target-tailored social engineering through messaging platforms such as WhatsApp and Telegram, followed by a seemingly authentic file. Lures include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass and MRI scan results.
Reported capabilities For the samples described, the FBI reports functions including screen and audio recording, cache capture, file compression and deletion, and staged exfiltration through Telegram. The advisory reports persistence across reboot, data collection and other functions; capabilities vary by sample and are not present in every observed infection.
Guidance Provides technical indicators for defenders and encourages reporting suspicious or criminal activity to IC3 or local FBI Cyber Squads. Provides individual and administrator mitigation guidance, including safe software sourcing, updates, antivirus, phishing-resistant MFA and monitoring.

What can CHOSEN BRICK do?

The joint advisory says observed CHOSEN BRICK infections targeted Windows. It describes the malware as persistent across reboot through a Windows registry Run key and says it can add exclusions to Microsoft Defender. Each observed device contacted a distinct Telegram bot ID.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Reported capabilities include enumerating processes and system information; capturing screens and microphone audio; collecting Telegram and WhatsApp browser data; stealing email content; downloading additional malware; and deleting files. The advisory says at least one sample could wipe a system. Data may be exfiltrated through Telegram bots or cloud object stores, and recent variants also used HTTPS or SOCKS5 proxies. These are capabilities documented across samples, not a claim that every infection performs every action.

What should you do if someone sends you a file on Telegram?

  • Do not open an unexpected file just because the sender or subject looks familiar. Attackers may impersonate a person you know or tailor a lure to your interests, work or circumstances.
  • Verify through a separate, trusted route. Contact the person or organization using a phone number, address or account you already know—not contact details or links in the message—and ask whether they sent the file and why it is needed.
  • Do not install software from a message link or attachment. If you need a program, find it through the legitimate vendor’s site or an official app store. Treat a request to install a “viewer,” “update” or utility to see a document as a reason to stop and verify.
  • Keep Windows and apps updated, and leave antivirus enabled and updated. Heed Microsoft SmartScreen warnings rather than bypassing them to open a file.
  • If the message claims to be technical support, do not rely on the claim in the message. Find the organization’s official support channel independently and ask it to confirm the request before downloading anything.

What should organizations and administrators do?

The joint NCSC/FBI/AIVD advisory recommends protections that reduce both the chance of a successful lure and the damage an infection can cause:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Require phishing-resistant multifactor authentication (MFA), especially for important accounts.
  • Use managed devices with controls such as application allowlisting and antivirus.
  • Apply email security controls, and monitor endpoints and networks for suspicious activity.
  • Search collected logs for the technical indicators of compromise (IOCs) published in the joint advisory.

Administrators should use the indicators and technical details in the relevant advisory, rather than assuming that an indicator from one report identifies the other malware family. The FBI FLASH includes technical indicators for defenders; the joint advisory supplies its own CHOSEN BRICK analysis and indicators.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What if you already opened a suspicious file?

If the device belongs to your employer, school or another organization, follow its incident-reporting process promptly. Tell the security team what you opened, when, and where it came from; do not delete evidence or keep using the device for sensitive work unless responders advise you to. If it is a personal device, seek qualified incident-response help. The advisories do not endorse a particular consumer security product as a substitute for investigating a suspected compromise.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The FBI encourages reporting suspicious or criminal activity to the Internet Crime Complaint Center (IC3) and provides a route to contact local FBI Cyber Squads. Organizations should also use their established security and incident-response channels.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.