Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and Journalists

Iranian MOIS-Linked Actor Uses Telegram-Controlled (TL-2026-2526), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-15 and last reviewed 2026-09-27. It is attributed to Iran Ministry of Intelligence (Iran) with high confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1005, T1027.013, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-2526

Threat ID
TL-2026-2526
Also known as
HEAVYGRAM, CHOSEN BRICK
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-15
Last reviewed
2026-09-27
Attribution
Iran Ministry of Intelligence
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
civil society, journalism, human-rights-advocacy, dissident-groups
Target regions
united kingdom, united states of america, netherlands, Worldwide
Detection rules
9
Indicators of compromise
28
Updates
2026-09-27 · 2 updates · revalidated 2× · latest source

Malware and tooling in Iranian MOIS-Linked Actor Uses Telegram-Controlled

Malware and tooling: CHOSEN BRICK, HEAVYGRAM

The FBI, UK NCSC, and Netherlands' AIVD issued a joint advisory on 15 September 2026 attributing a Windows surveillance-malware campaign to Iran's Ministry of Intelligence and Security (MOIS), tracked as HEAVYGRAM (FBI) or CHOSEN BRICK (NCSC). The malware is controlled through a per-victim Telegram bot and, in newer variants, proxies that Telegram traffic through IPRoyal or Lightning Proxies while exfiltrating data via abused Vultr, Storj, and Backblaze B2 cloud storage.

How Iranian MOIS-Linked Actor Uses Telegram-Controlled works

HEAVYGRAM/CHOSEN BRICK is a two-stage Windows spyware family that Iran's Ministry of Intelligence and Security (MOIS) has used since at least autumn 2023 to surveil dissidents, journalists, and activists opposed to the Iranian government in the UK, US, and Netherlands, and worldwide. On 15 September 2026, the UK National Cyber Security Centre, the FBI, and the Netherlands' AIVD jointly published an advisory naming the malware -- HEAVYGRAM per the FBI, CHOSEN BRICK per the NCSC -- and updating an earlier FBI FLASH alert (FLASH-20260320-001, 20 March 2026) that first described Iranian actors using Telegram as C2 infrastructure against identified targets.

Initial access is social engineering delivered over messaging platforms (WhatsApp, Telegram) and social media: operators impersonate trusted contacts, celebrities, or technical support and persuade targets to download files disguised as legitimate software -- observed lures include Pictory, KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player, and fabricated MRI scan results. A convincing decoy installation screen displays while the malware installs in the background.

The attack chain uses chained loaders: base64-encoded PowerShell one-liners (ps.ps1, cmd.ps1) fetch archives from an abused Vultr Object Storage bucket; a heavily padded VBScript (183,897 bytes across 63,791 lines, with only ~11 lines of functional deobfuscation logic) decodes and runs only when the host disk exceeds 50GB, a sandbox/VM-evasion check. The resulting stage-2 payload (Smqdservice.exe, a 23.1MB ZIP bundling a Python 3.11 runtime) establishes a dedicated per-victim Telegram bot for bidirectional command and control, isolating each victim's traffic from others and blending with legitimate Telegram usage. Newer variants proxy this Telegram traffic through commercial residential/proxy services (IPRoyal, Lightning Proxies) to further obscure C2 communications.

Capabilities include screenshot capture, microphone activation for audio recording, theft of Telegram and WhatsApp data from browsers, saved-password and email theft, process/system enumeration, additional-malware downloads, file deletion, and -- in at least one observed version -- full disk/file wiping. The malware persists via a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) under the value names SMQDService or winappx, and evades detection by instructing Microsoft Defender to exclude the malware's own working directories from scanning. Data stolen from victims has subsequently appeared on pro-Iranian leak/doxxing sites; the US Department of Justice seized four such sites in March 2026.

MITRE ATT&CK techniques used in TL-2026-2526

Collection

T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture; T1213 Data from Information Repositories; T1560.001 Archive via Utility

Stealth

T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration Over Web Service

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 PowerShell; T1059.005 Visual Basic; T1204.002 Malicious File

Command and Control

T1071.001 Application Layer Protocol; T1090.002 External Proxy; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer

Impact

T1485 Data Destruction

Persistence

T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

Initial Access

T1566 Phishing; T1566.003 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585.001 Establish Accounts

Reconnaissance

T1589 Gather Victim Identity Information

Defense Impairment

T1685 Disable or Modify Tools

Affected products and versions in Iranian MOIS-Linked Actor Uses Telegram-Controlled

  • Microsoft — Windows
    Vulnerable versions: all supported Windows desktop versions

Remediation for Iranian MOIS-Linked Actor Uses Telegram-Controlled

Immediate actions

  • Search endpoint and network logs for the provided file hashes, filenames, registry Run-key values, mutex names, and C2 domains
  • Block/alert on outbound traffic to api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net where not business-justified
  • Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries named SMQDService or winappx

Workarounds

  • Avoid installing software received as attachments or links in messaging apps; use official app stores/vendor sites only
  • Enable automatic OS and application updates
  • Maintain active, updated antivirus/EDR and do not dismiss SmartScreen warnings
  • Report suspected compromise to NCSC (report.ncsc.gov.uk), FBI IC3 (www.ic3.gov), or AIVD/local law enforcement

Longer-term hardening

  • Deploy phishing-resistant MFA and application allowlisting for at-risk populations (journalists, activists, dissidents)
  • Deploy endpoint and network monitoring capable of detecting Telegram Bot API used as a C2 channel
  • Provide digital-security training on messaging-platform social engineering to high-risk individuals

Timeline of Iranian MOIS-Linked Actor Uses Telegram-Controlled

  • FBI and NCSC date the HEAVYGRAM/CHOSEN BRICK campaign's earliest observed activity to autumn 2023.
  • Advisory partners document sustained CHOSEN BRICK/HEAVYGRAM targeting of individuals in the UK, US, and Netherlands from at least 2025 onward.
  • Personal details of prior CHOSEN BRICK/HEAVYGRAM victims begin appearing on pro-Iranian leak sites, predating the March 2026 DOJ seizure and raising physical-safety concerns for targeted dissidents and journalists.
  • The US Justice Department seizes four pro-Iranian leak sites that had published personal data stolen from campaign victims.
  • FBI/IC3 publish Cybersecurity Advisory CSA 260320 detailing the Telegram-C2 malware campaign and initial IOCs.
  • FBI issues FLASH-20260320-001, warning that Iran MOIS cyber actors use Telegram bots as C2 infrastructure to push malware to dissidents, journalists, and opposition-linked individuals.
  • The Hacker News, Jerusalem Post, and other outlets publicly report on the joint advisory and campaign technical details.
  • NCSC Director of Operations Paul Chichester states that Iran "ruthlessly uses digital surveillance to repress critics of the regime," noting stolen victim data appearing on pro-Iranian leak sites.
  • UK NCSC, FBI, and Netherlands AIVD jointly publish an advisory naming the malware HEAVYGRAM (FBI) and CHOSEN BRICK (NCSC), formally attributing it to Iran's Ministry of Intelligence and Security.
  • Help Net Security and Security Affairs publish follow-on technical analyses adding further IOCs (proxy domains, mutex identifiers, registry persistence values) for CHOSEN BRICK.
  • Truesec publishes a blog analysis corroborating the Telegram/WhatsApp social-engineering delivery chain and fake-MRI-scan/fake-application lures, and notes the malware's lack of lateral-movement functionality, indicating deliberate single-device targeting.

Update history for TL-2026-2526

Sources cited for Iranian MOIS-Linked Actor Uses Telegram-Controlled

More in malware

Detection coverage for TL-2026-2526

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2526 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats