Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and Journalists
Iranian MOIS-Linked Actor Uses Telegram-Controlled (TL-2026-2526), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-15 and last reviewed 2026-09-27. It is attributed to Iran Ministry of Intelligence (Iran) with high confidence, affects Microsoft Windows, maps to 30 MITRE ATT&CK techniques (T1005, T1027.013, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2526
- Threat ID
- TL-2026-2526
- Also known as
- HEAVYGRAM, CHOSEN BRICK
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-15
- Last reviewed
- 2026-09-27
- Attribution
- Iran Ministry of Intelligence
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- civil society, journalism, human-rights-advocacy, dissident-groups
- Target regions
- united kingdom, united states of america, netherlands, Worldwide
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-09-27 · 2 updates · revalidated 2× · latest source
Malware and tooling in Iranian MOIS-Linked Actor Uses Telegram-Controlled
Malware and tooling: CHOSEN BRICK, HEAVYGRAM
The FBI, UK NCSC, and Netherlands' AIVD issued a joint advisory on 15 September 2026 attributing a Windows surveillance-malware campaign to Iran's Ministry of Intelligence and Security (MOIS), tracked as HEAVYGRAM (FBI) or CHOSEN BRICK (NCSC). The malware is controlled through a per-victim Telegram bot and, in newer variants, proxies that Telegram traffic through IPRoyal or Lightning Proxies while exfiltrating data via abused Vultr, Storj, and Backblaze B2 cloud storage.
How Iranian MOIS-Linked Actor Uses Telegram-Controlled works
HEAVYGRAM/CHOSEN BRICK is a two-stage Windows spyware family that Iran's Ministry of Intelligence and Security (MOIS) has used since at least autumn 2023 to surveil dissidents, journalists, and activists opposed to the Iranian government in the UK, US, and Netherlands, and worldwide. On 15 September 2026, the UK National Cyber Security Centre, the FBI, and the Netherlands' AIVD jointly published an advisory naming the malware -- HEAVYGRAM per the FBI, CHOSEN BRICK per the NCSC -- and updating an earlier FBI FLASH alert (FLASH-20260320-001, 20 March 2026) that first described Iranian actors using Telegram as C2 infrastructure against identified targets.
Initial access is social engineering delivered over messaging platforms (WhatsApp, Telegram) and social media: operators impersonate trusted contacts, celebrities, or technical support and persuade targets to download files disguised as legitimate software -- observed lures include Pictory, KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player, and fabricated MRI scan results. A convincing decoy installation screen displays while the malware installs in the background.
The attack chain uses chained loaders: base64-encoded PowerShell one-liners (ps.ps1, cmd.ps1) fetch archives from an abused Vultr Object Storage bucket; a heavily padded VBScript (183,897 bytes across 63,791 lines, with only ~11 lines of functional deobfuscation logic) decodes and runs only when the host disk exceeds 50GB, a sandbox/VM-evasion check. The resulting stage-2 payload (Smqdservice.exe, a 23.1MB ZIP bundling a Python 3.11 runtime) establishes a dedicated per-victim Telegram bot for bidirectional command and control, isolating each victim's traffic from others and blending with legitimate Telegram usage. Newer variants proxy this Telegram traffic through commercial residential/proxy services (IPRoyal, Lightning Proxies) to further obscure C2 communications.
Capabilities include screenshot capture, microphone activation for audio recording, theft of Telegram and WhatsApp data from browsers, saved-password and email theft, process/system enumeration, additional-malware downloads, file deletion, and -- in at least one observed version -- full disk/file wiping. The malware persists via a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) under the value names SMQDService or winappx, and evades detection by instructing Microsoft Defender to exclude the malware's own working directories from scanning. Data stolen from victims has subsequently appeared on pro-Iranian leak/doxxing sites; the US Department of Justice seized four such sites in March 2026.
MITRE ATT&CK techniques used in TL-2026-2526
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture; T1213 Data from Information Repositories; T1560.001 Archive via Utility
Stealth
T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration Over Web Service
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1059.005 Visual Basic; T1204.002 Malicious File
Command and Control
T1071.001 Application Layer Protocol; T1090.002 External Proxy; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer
Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1555.003 Credentials from Web Browsers
Initial Access
T1566 Phishing; T1566.003 Phishing
Resource Development
T1583 Acquire Infrastructure; T1585.001 Establish Accounts
Reconnaissance
T1589 Gather Victim Identity Information
Defense Impairment
Affected products and versions in Iranian MOIS-Linked Actor Uses Telegram-Controlled
- Microsoft — Windows
Vulnerable versions: all supported Windows desktop versions
Remediation for Iranian MOIS-Linked Actor Uses Telegram-Controlled
Immediate actions
- Search endpoint and network logs for the provided file hashes, filenames, registry Run-key values, mutex names, and C2 domains
- Block/alert on outbound traffic to api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net where not business-justified
- Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries named SMQDService or winappx
Workarounds
- Avoid installing software received as attachments or links in messaging apps; use official app stores/vendor sites only
- Enable automatic OS and application updates
- Maintain active, updated antivirus/EDR and do not dismiss SmartScreen warnings
- Report suspected compromise to NCSC (report.ncsc.gov.uk), FBI IC3 (www.ic3.gov), or AIVD/local law enforcement
Longer-term hardening
- Deploy phishing-resistant MFA and application allowlisting for at-risk populations (journalists, activists, dissidents)
- Deploy endpoint and network monitoring capable of detecting Telegram Bot API used as a C2 channel
- Provide digital-security training on messaging-platform social engineering to high-risk individuals
Timeline of Iranian MOIS-Linked Actor Uses Telegram-Controlled
- FBI and NCSC date the HEAVYGRAM/CHOSEN BRICK campaign's earliest observed activity to autumn 2023.
- Advisory partners document sustained CHOSEN BRICK/HEAVYGRAM targeting of individuals in the UK, US, and Netherlands from at least 2025 onward.
- Personal details of prior CHOSEN BRICK/HEAVYGRAM victims begin appearing on pro-Iranian leak sites, predating the March 2026 DOJ seizure and raising physical-safety concerns for targeted dissidents and journalists.
- The US Justice Department seizes four pro-Iranian leak sites that had published personal data stolen from campaign victims.
- FBI/IC3 publish Cybersecurity Advisory CSA 260320 detailing the Telegram-C2 malware campaign and initial IOCs.
- FBI issues FLASH-20260320-001, warning that Iran MOIS cyber actors use Telegram bots as C2 infrastructure to push malware to dissidents, journalists, and opposition-linked individuals.
- The Hacker News, Jerusalem Post, and other outlets publicly report on the joint advisory and campaign technical details.
- NCSC Director of Operations Paul Chichester states that Iran "ruthlessly uses digital surveillance to repress critics of the regime," noting stolen victim data appearing on pro-Iranian leak sites.
- UK NCSC, FBI, and Netherlands AIVD jointly publish an advisory naming the malware HEAVYGRAM (FBI) and CHOSEN BRICK (NCSC), formally attributing it to Iran's Ministry of Intelligence and Security.
- Help Net Security and Security Affairs publish follow-on technical analyses adding further IOCs (proxy domains, mutex identifiers, registry persistence values) for CHOSEN BRICK.
- Truesec publishes a blog analysis corroborating the Telegram/WhatsApp social-engineering delivery chain and fake-MRI-scan/fake-application lures, and notes the malware's lack of lateral-movement functionality, indicating deliberate single-device targeting.
Update history for TL-2026-2526
- 2026-09-27 — CHOSEN BRICK: Iranian MOIS Espionage Malware Targeting Exiled Dissidents, Activists and Journalists (aka HEAVYGRAM): What changed No change to severity (HIGH), exploitability (ACTIVE), status (ACTIVE), or attribution confidence (HIGH) — the existing record's MOIS attribution already matches the joint advisory's formal conclusion. New indicators (1) One ne
- 2026-09-16 — Iranian MOIS-Linked CHOSEN BRICK (FBI: HEAVYGRAM) Spyware Targets Windows Systems of Dissidents, Activists, and Journalists: What changed No field escalations (severity, exploitability, status, and attribution confidence are unchanged). The record is enriched with pre-compromise and post-exploitation technique coverage and two anti-sandbox mutexes. New indicators
Sources cited for Iranian MOIS-Linked Actor Uses Telegram-Controlled
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents, Journalists
- Iranian cyber targeting of dissidents, activists and journalists
- Joint Cybersecurity Advisory: Iran MOIS Telegram-Controlled Malware (CSA 260915-2)
- Cybersecurity Advisory: HEAVYGRAM/CHOSEN BRICK (CSA 260915)
- Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets
- FLASH-20260320-001: Government of Iran Cyberactors Deploy Telegram C2 to Push Malware to Identified Targets
- Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets (CSA 260320)
- FBI Releases Cybersecurity Advisory on Previously Undisclosed Iranian Malware Used to Monitor Dissidents and Travel and Telecommunications Companies
- US, UK, Netherlands warn of Iranian CHOSEN BRICK spyware targeting press
- Analyzing Iranian Tradecraft: Leveraging Loader Scripts and Telegram for C2
- Iran-linked actors use Telegram as C2 in malware attacks on dissidents
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-2526
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2526 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.