Iranian malware steals Telegram and WhatsApp data from targets
Brief
Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since at least 2025 and relies heavily on social engineering, while also using Telegram infrastructure for command-and-control. The …
The post Iranian malware steals Telegram and WhatsApp data from targets appeared first on CyberInsider .
