Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies
Chosen Brick (TL-2026-2534), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-16. It is attributed to Iranian state cyber actors (Iran) with medium confidence, affects Microsoft Windows, maps to 16 MITRE ATT&CK techniques (T1005, T1057, T1082), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2534
- Threat ID
- TL-2026-2534
- Also known as
- HEAVYGRAM
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-16
- Last reviewed
- 2026-09-16
- Attribution
- Iranian state cyber actors
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- news - media, civil society, ngo
- Target regions
- Europe, North America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Chosen Brick
Malware and tooling: CHOSEN BRICK, HEAVYGRAM, telegram, Adobe Flash Player, KeePass, Norton Antivirus, Pictory, RunwayML
UK NCSC, US FBI, and the Netherlands' AIVD jointly exposed CHOSEN BRICK, Windows-only surveillance malware used by Iranian state cyber actors against dissidents, activists, and journalists. Delivered via WhatsApp/Telegram social engineering with disguised installers and decoy documents (including a fake MRI scan), it captures screenshots and microphone audio, steals browser chat data and email, and exfiltrates via a per-victim Telegram bot and abused cloud storage services.
How Chosen Brick works
CHOSEN BRICK is a Windows-only surveillance implant that a joint September 15, 2026 advisory from the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands' General Intelligence and Security Service (AIVD) attributed to Iranian state cyber actors. The campaign has targeted dissidents, activists, and journalists perceived as threats to the Iranian regime, with documented victims in the UK, US, and Netherlands since at least 2025 (Recorded Future/The Record additionally references related persona activity dating to fall 2023).
The attack chain begins with extensive social engineering on WhatsApp and Telegram: operators research targets, impersonate trusted contacts or technical-support personnel, and build rapport over multiple interactions before delivering a malicious file. Observed lures include installers disguised as legitimate software (Norton Antivirus, Adobe Flash Player, KeePass, Telegram itself, and the AI tools Pictory and RunwayML) and fabricated documents, most notably a fake MRI scan showing a disc herniation sent to a specific target described as an 'enemy of the regime.' When opened, the dropper displays a decoy screen (e.g., a fake document or installer UI) while silently deploying CHOSEN BRICK in the background.
Once installed, CHOSEN BRICK establishes persistence via a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) so it relaunches at every logon, and attempts to add Microsoft Defender exclusions to reduce detection and removal. Its collection capability is broad: screenshot capture, microphone-based audio recording, harvesting of Telegram/WhatsApp chat data and browser-stored data, email content theft, contact and social-media message collection (enabling 'pattern of life' mapping of the target), process enumeration and system reconnaissance, additional payload download, and destructive data-wiping/deletion commands.
Command and control runs over the Telegram Bot API, with each infected endpoint assigned a distinct, per-victim Telegram bot for operational segmentation; more recent samples wrap this traffic in HTTPS or SOCKS5 proxy services (observed proxy providers include iproyal.com and lightningproxies.net) to complicate network-based detection. Exfiltrated data is sent both through the per-victim Telegram bot channel and to commodity cloud object-storage services — Vultr Object Storage (vultrobjects.com), Storj (storjshare.io), and Backblaze B2 (backblazeb2.com) were named as abused exfiltration destinations. Stolen material from some victims has subsequently appeared on pro-Iranian leak sites, with Recorded Future/The Record associating this publication activity with the 'Handala Hack' persona; the same reporting (single-sourced relative to the joint government advisory) attributes the operation to Iran's Ministry of Intelligence and Security (MOIS) and notes possible links to the 'Homeland Justice' persona, and cites an FBI tracking alias of HEAVYGRAM for the malware family.
No CVE or exploited vulnerability is associated with this campaign — initial access is entirely social-engineering-driven rather than exploit-based, and no public IOC file hashes were available in open reporting at publication time; the joint advisory instead recommends monitoring DNS and web-proxy logs for unexpected connections to the abused Telegram/cloud-storage infrastructure.
MITRE ATT&CK techniques used in TL-2026-2534
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114.001 Email Collection: Local Email Collection; T1123 Audio Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1090.002 Proxy: External Proxy; T1102.002 Web Service: Bidirectional Communication
Execution
T1204.002 User Execution: Malicious File
Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
T1566.003 Phishing: Spearphishing via Service
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Reconnaissance
T1589 Gather Victim Identity Information
Defense Evasion
defense-impairment
Affected products and versions in Chosen Brick
- Microsoft — Windows
Vulnerable versions: all supported consumer/desktop Windows versions (delivered via social engineering, not exploit)
Remediation for Chosen Brick
Immediate actions
- Monitor DNS and web-proxy logs for connections to api.telegram.org, vultrobjects.com, storjshare.io, and backblazeb2.com that are not expected as part of normal business use, per NCSC guidance
- Audit Microsoft Defender exclusion lists for unauthorized additions
- Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for unrecognized entries
Workarounds
- Verify installer authenticity and publisher signature before running software received via messaging apps, even from apparent known contacts
- Treat unsolicited medical or personal documents received over messaging apps as high-risk attachments
Longer-term hardening
- Security-awareness training on messaging-app (WhatsApp/Telegram) impersonation and rapport-building social engineering, particularly for high-risk individuals (journalists, activists, dissidents)
- Deploy EDR with behavioral detection for screen/microphone capture APIs and unsigned installer execution
- Application allowlisting to block unsigned or unexpected installer execution from user-writable paths
Timeline of Chosen Brick
- Recorded Future/The Record reports related Iranian surveillance-campaign persona activity dating to approximately fall 2023 (predates confirmed CHOSEN BRICK attribution; approximate date, exact date not specified in source).
- Joint advisory and press reporting describe CHOSEN BRICK as active against victims in the UK, US, and Netherlands 'at least since 2025'; exact first-observed date not disclosed in public sources.
- GBHackers, CyberPress, The Record, Jerusalem Post, and gblock.app publish technical write-ups summarizing the joint advisory's findings on delivery lures, persistence, and C2/exfiltration infrastructure.
- FBI publishes IC3 Cybersecurity Advisory CSA-2026-260915 documenting CHOSEN BRICK alongside the joint NCSC/AIVD release.
- UK NCSC, US FBI, and Netherlands AIVD jointly publish an advisory exposing CHOSEN BRICK and attributing it to Iranian state cyber actors.
- SecurityWeek publishes coverage of the joint advisory, the source article that triggered this threat record.
Sources cited for Chosen Brick
- US, UK, Dutch Agencies Expose Iranian 'Chosen Brick' Surveillance Malware
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
- Iranian cyber targeting of dissidents, activists and journalists
- UK and allies expose spyware used by Iranian state actors (joint advisory PDF)
- FBI IC3 Cybersecurity Advisory CSA-2026-260915 (CHOSEN BRICK)
- Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
- CHOSEN BRICK Malware Lets Iranian State Hackers Steal Emails, WhatsApp and Telegram Data
- Iranian cyber spies used fake MRI scan results to hack 'enemy of regime'
- US, UK, Netherlands warn of Iranian CHOSEN BRICK spyware targeting press
- Iran's CHOSEN BRICK Spyware Reads Journalists' Email
More in malware
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists
Detection coverage for TL-2026-2534
As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2534 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.