Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies

Chosen Brick (TL-2026-2534), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-16. It is attributed to Iranian state cyber actors (Iran) with medium confidence, affects Microsoft Windows, maps to 16 MITRE ATT&CK techniques (T1005, T1057, T1082), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2534

Threat ID
TL-2026-2534
Also known as
HEAVYGRAM
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-16
Last reviewed
2026-09-16
Attribution
Iranian state cyber actors
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
news - media, civil society, ngo
Target regions
Europe, North America, Middle East
Detection rules
9
Indicators of compromise
18

Malware and tooling in Chosen Brick

Malware and tooling: CHOSEN BRICK, HEAVYGRAM, telegram, Adobe Flash Player, KeePass, Norton Antivirus, Pictory, RunwayML

UK NCSC, US FBI, and the Netherlands' AIVD jointly exposed CHOSEN BRICK, Windows-only surveillance malware used by Iranian state cyber actors against dissidents, activists, and journalists. Delivered via WhatsApp/Telegram social engineering with disguised installers and decoy documents (including a fake MRI scan), it captures screenshots and microphone audio, steals browser chat data and email, and exfiltrates via a per-victim Telegram bot and abused cloud storage services.

How Chosen Brick works

CHOSEN BRICK is a Windows-only surveillance implant that a joint September 15, 2026 advisory from the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands' General Intelligence and Security Service (AIVD) attributed to Iranian state cyber actors. The campaign has targeted dissidents, activists, and journalists perceived as threats to the Iranian regime, with documented victims in the UK, US, and Netherlands since at least 2025 (Recorded Future/The Record additionally references related persona activity dating to fall 2023).

The attack chain begins with extensive social engineering on WhatsApp and Telegram: operators research targets, impersonate trusted contacts or technical-support personnel, and build rapport over multiple interactions before delivering a malicious file. Observed lures include installers disguised as legitimate software (Norton Antivirus, Adobe Flash Player, KeePass, Telegram itself, and the AI tools Pictory and RunwayML) and fabricated documents, most notably a fake MRI scan showing a disc herniation sent to a specific target described as an 'enemy of the regime.' When opened, the dropper displays a decoy screen (e.g., a fake document or installer UI) while silently deploying CHOSEN BRICK in the background.

Once installed, CHOSEN BRICK establishes persistence via a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) so it relaunches at every logon, and attempts to add Microsoft Defender exclusions to reduce detection and removal. Its collection capability is broad: screenshot capture, microphone-based audio recording, harvesting of Telegram/WhatsApp chat data and browser-stored data, email content theft, contact and social-media message collection (enabling 'pattern of life' mapping of the target), process enumeration and system reconnaissance, additional payload download, and destructive data-wiping/deletion commands.

Command and control runs over the Telegram Bot API, with each infected endpoint assigned a distinct, per-victim Telegram bot for operational segmentation; more recent samples wrap this traffic in HTTPS or SOCKS5 proxy services (observed proxy providers include iproyal.com and lightningproxies.net) to complicate network-based detection. Exfiltrated data is sent both through the per-victim Telegram bot channel and to commodity cloud object-storage services — Vultr Object Storage (vultrobjects.com), Storj (storjshare.io), and Backblaze B2 (backblazeb2.com) were named as abused exfiltration destinations. Stolen material from some victims has subsequently appeared on pro-Iranian leak sites, with Recorded Future/The Record associating this publication activity with the 'Handala Hack' persona; the same reporting (single-sourced relative to the joint government advisory) attributes the operation to Iran's Ministry of Intelligence and Security (MOIS) and notes possible links to the 'Homeland Justice' persona, and cites an FBI tracking alias of HEAVYGRAM for the malware family.

No CVE or exploited vulnerability is associated with this campaign — initial access is entirely social-engineering-driven rather than exploit-based, and no public IOC file hashes were available in open reporting at publication time; the joint advisory instead recommends monitoring DNS and web-proxy logs for unexpected connections to the abused Telegram/cloud-storage infrastructure.

MITRE ATT&CK techniques used in TL-2026-2534

Collection

T1005 Data from Local System; T1113 Screen Capture; T1114.001 Email Collection: Local Email Collection; T1123 Audio Capture

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Command and Control

T1090.002 Proxy: External Proxy; T1102.002 Web Service: Bidirectional Communication

Execution

T1204.002 User Execution: Malicious File

Impact

T1485 Data Destruction

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.003 Phishing: Spearphishing via Service

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Reconnaissance

T1589 Gather Victim Identity Information

Defense Evasion

T1684.001 Impersonation

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Chosen Brick

  • Microsoft — Windows
    Vulnerable versions: all supported consumer/desktop Windows versions (delivered via social engineering, not exploit)

Remediation for Chosen Brick

Immediate actions

  • Monitor DNS and web-proxy logs for connections to api.telegram.org, vultrobjects.com, storjshare.io, and backblazeb2.com that are not expected as part of normal business use, per NCSC guidance
  • Audit Microsoft Defender exclusion lists for unauthorized additions
  • Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for unrecognized entries

Workarounds

  • Verify installer authenticity and publisher signature before running software received via messaging apps, even from apparent known contacts
  • Treat unsolicited medical or personal documents received over messaging apps as high-risk attachments

Longer-term hardening

  • Security-awareness training on messaging-app (WhatsApp/Telegram) impersonation and rapport-building social engineering, particularly for high-risk individuals (journalists, activists, dissidents)
  • Deploy EDR with behavioral detection for screen/microphone capture APIs and unsigned installer execution
  • Application allowlisting to block unsigned or unexpected installer execution from user-writable paths

Timeline of Chosen Brick

  • Recorded Future/The Record reports related Iranian surveillance-campaign persona activity dating to approximately fall 2023 (predates confirmed CHOSEN BRICK attribution; approximate date, exact date not specified in source).
  • Joint advisory and press reporting describe CHOSEN BRICK as active against victims in the UK, US, and Netherlands 'at least since 2025'; exact first-observed date not disclosed in public sources.
  • GBHackers, CyberPress, The Record, Jerusalem Post, and gblock.app publish technical write-ups summarizing the joint advisory's findings on delivery lures, persistence, and C2/exfiltration infrastructure.
  • FBI publishes IC3 Cybersecurity Advisory CSA-2026-260915 documenting CHOSEN BRICK alongside the joint NCSC/AIVD release.
  • UK NCSC, US FBI, and Netherlands AIVD jointly publish an advisory exposing CHOSEN BRICK and attributing it to Iranian state cyber actors.
  • SecurityWeek publishes coverage of the joint advisory, the source article that triggered this threat record.

Sources cited for Chosen Brick

More in malware

Detection coverage for TL-2026-2534

As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2534 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats