Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists

Iranian State Actors Deploy CHOSEN BRICK Windows Malware to (TL-2026-2543), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-16. It is attributed to Iran Ministry of Intelligence (Iran) with high confidence, affects Microsoft Windows, maps to 17 MITRE ATT&CK techniques (T1005, T1057, T1082), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2543

Threat ID
TL-2026-2543
Also known as
HEAVYGRAM
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-16
Last reviewed
2026-09-16
Attribution
Iran Ministry of Intelligence
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
civil society, news - media, human rights, ngo
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
19

Malware and tooling in Iranian State Actors Deploy CHOSEN BRICK Windows Malware to

Malware and tooling: CHOSEN BRICK, HEAVYGRAM, telegram, Adobe Flash Player, KeePass, Norton Antivirus, Pictory, RunwayML, Telegram, Telegram Bot API

Iranian state actors operating on behalf of Iran's Ministry of Intelligence and Security (MOIS) are using Windows spyware known as CHOSEN BRICK (FBI designation: HEAVYGRAM) to surveil dissidents, activists, and journalists in the US, UK, and Netherlands, per a joint 15 September 2026 NCSC/FBI/AIVD advisory. Victims are lured via WhatsApp/Telegram social engineering into installing trojanized apps, after which the malware harvests communications, screenshots, and audio over a per-victim Telegram-bot C2 channel and can fully wipe the infected device.

How Iranian State Actors Deploy CHOSEN BRICK Windows Malware to works

CHOSEN BRICK (tracked separately by the FBI as HEAVYGRAM, the same malware lineage first linked to activity dating to autumn 2023) is a Windows-only surveillance and data-theft implant deployed by Iranian state cyber actors operating for Iran's Ministry of Intelligence and Security (MOIS). A joint advisory published 15 September 2026 by the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (via IC3, CSA 260915-2), and the Netherlands' General Intelligence and Security Service (AIVD) attributes an active campaign, documented since at least 2025, targeting dissidents, activists, and journalists in the US, UK, and Netherlands who are perceived as threats to the Iranian regime.

Operators build rapport with targets over WhatsApp and Telegram, impersonating trusted acquaintances or platform/IT technical-support representatives, before delivering a malicious file disguised as a legitimate application (Pictory, RunwayML, Norton Antivirus, Telegram itself, Adobe Flash Player, KeePass) or a fabricated document such as an MRI scan result. Corporate targets whose devices are protected by enterprise security controls are frequently redirected toward less-defended personal devices. Once executed, CHOSEN BRICK/HEAVYGRAM establishes persistence via the HKCU Run registry key (observed values SMQDService and winappx), guards against re-infection using hardcoded mutexes (ytyjyujyu, noi672pp434awkc12f), and adds Microsoft Defender exclusions to reduce the likelihood its files are scanned or removed.

The implant collects screenshots, microphone audio, running-process and system information, email content, and WhatsApp/Telegram browser chat data, and can download additional payloads. Command and control is conducted through per-victim Telegram bots (a unique bot ID per infected machine, preventing cross-victim contamination), with newer variants relaying that Telegram traffic through commercial HTTPS/SOCKS5 proxy services (IPRoyal, LightningProxies) to obscure the C2 channel; stolen data is also exfiltrated to legitimate cloud object-storage services (Backblaze B2, Vultr Object Storage, Storj). At least one observed variant carries a full data-wipe capability, giving operators a destructive option against journalists' and activists' devices in addition to ongoing surveillance.

MITRE ATT&CK techniques used in TL-2026-2543

Collection

T1005 Data from Local System; T1113 Screen Capture; T1114.001 Local Email Collection; T1123 Audio Capture

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Command and Control

T1090.002 External Proxy; T1102.002 Bidirectional Communication

Execution

T1204.002 Malicious File

Defense Evasion

T1480.002 Mutual Exclusion

Impact

T1485 Data Destruction

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.003 Spearphishing via Service

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1585.001 Social Media Accounts

Reconnaissance

T1589 Gather Victim Identity Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Iranian State Actors Deploy CHOSEN BRICK Windows Malware to

  • Microsoft — Windows
    Vulnerable versions: All supported Windows versions (malware is delivered via social engineering, not a software vulnerability)

Remediation for Iranian State Actors Deploy CHOSEN BRICK Windows Malware to

Immediate actions

  • Search endpoint logs and the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key for the reported values SMQDService and winappx
  • Search for the reported mutexes ytyjyujyu and noi672pp434awkc12f as execution-guardrail indicators of infection
  • Review Microsoft Defender exclusion lists for unexpected entries, particularly paths resembling C:\Windows \SysWOW64 (note the inserted space)
  • Monitor or restrict egress to backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net where not business-required
  • Report suspected compromises to national authorities: UK report.ncsc.gov.uk, US FBI IC3 (ic3.gov), Netherlands AIVD

Workarounds

  • Do not install software received via links or attachments sent over WhatsApp or Telegram; install only from official app stores or vendor sites
  • Do not disable SmartScreen or antivirus warnings when prompted during software installation
  • Keep operating systems and applications configured for automatic updates

Longer-term hardening

  • Deploy phishing-resistant MFA for at-risk individuals such as journalists, activists, and dissidents
  • Enable application allowlisting and endpoint monitoring to flag unauthorized Registry Run-key modifications and new Defender exclusions
  • Provide social-engineering awareness training focused on WhatsApp/Telegram impersonation of trusted contacts and IT support staff
  • Segment and separately monitor personal devices used by high-risk individuals who also hold corporate access

Timeline of Iranian State Actors Deploy CHOSEN BRICK Windows Malware to

  • FBI begins tracking a malware family later publicly named HEAVYGRAM (NCSC designation: CHOSEN BRICK), with the earliest linked activity dating to autumn 2023.
  • Iranian state actors observed deploying CHOSEN BRICK/HEAVYGRAM against dissidents, activists, and journalists in the US, UK, and Netherlands, per the joint advisory's documented 'at least 2025' activity window.
  • Advisory discloses that newer CHOSEN BRICK/HEAVYGRAM variants route Telegram C2 traffic through commercial HTTPS/SOCKS5 proxy services (IPRoyal, LightningProxies) to obscure communications.
  • Advisory documents the full attack chain: WhatsApp/Telegram rapport-building, delivery of trojanized apps or fraudulent MRI documents, HKCU registry Run-key persistence, Microsoft Defender exclusion abuse, per-victim Telegram-bot C2, and screenshot/audio/email/browser-chat collection culminating in optional additional-payload download or full data wipe.
  • UK NCSC, US FBI (via IC3 CSA 260915-2), and Netherlands AIVD jointly publish an advisory attributing CHOSEN BRICK/HEAVYGRAM to Iran's Ministry of Intelligence and Security (MOIS), detailing TTPs, IOCs, and mitigations.
  • BleepingComputer, SecurityWeek, The Hacker News, Infosecurity Magazine, and other outlets report on the joint advisory, amplifying public awareness of the campaign.
  • FBI publicly attributes HEAVYGRAM operations to Iran's MOIS, stating the tool is used to collect intelligence, conduct data leaks, and inflict reputational harm against regime-perceived opponents.

Sources cited for Iranian State Actors Deploy CHOSEN BRICK Windows Malware to

More in malware

Detection coverage for TL-2026-2543

As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2543 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats