Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists
Iranian State Actors Deploy CHOSEN BRICK Windows Malware to (TL-2026-2543), also tracked as HEAVYGRAM, is a high-severity malware campaign, first published 2026-09-16. It is attributed to Iran Ministry of Intelligence (Iran) with high confidence, affects Microsoft Windows, maps to 17 MITRE ATT&CK techniques (T1005, T1057, T1082), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2543
- Threat ID
- TL-2026-2543
- Also known as
- HEAVYGRAM
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-16
- Last reviewed
- 2026-09-16
- Attribution
- Iran Ministry of Intelligence
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- civil society, news - media, human rights, ngo
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Iranian State Actors Deploy CHOSEN BRICK Windows Malware to
Malware and tooling: CHOSEN BRICK, HEAVYGRAM, telegram, Adobe Flash Player, KeePass, Norton Antivirus, Pictory, RunwayML, Telegram, Telegram Bot API
Iranian state actors operating on behalf of Iran's Ministry of Intelligence and Security (MOIS) are using Windows spyware known as CHOSEN BRICK (FBI designation: HEAVYGRAM) to surveil dissidents, activists, and journalists in the US, UK, and Netherlands, per a joint 15 September 2026 NCSC/FBI/AIVD advisory. Victims are lured via WhatsApp/Telegram social engineering into installing trojanized apps, after which the malware harvests communications, screenshots, and audio over a per-victim Telegram-bot C2 channel and can fully wipe the infected device.
How Iranian State Actors Deploy CHOSEN BRICK Windows Malware to works
CHOSEN BRICK (tracked separately by the FBI as HEAVYGRAM, the same malware lineage first linked to activity dating to autumn 2023) is a Windows-only surveillance and data-theft implant deployed by Iranian state cyber actors operating for Iran's Ministry of Intelligence and Security (MOIS). A joint advisory published 15 September 2026 by the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (via IC3, CSA 260915-2), and the Netherlands' General Intelligence and Security Service (AIVD) attributes an active campaign, documented since at least 2025, targeting dissidents, activists, and journalists in the US, UK, and Netherlands who are perceived as threats to the Iranian regime.
Operators build rapport with targets over WhatsApp and Telegram, impersonating trusted acquaintances or platform/IT technical-support representatives, before delivering a malicious file disguised as a legitimate application (Pictory, RunwayML, Norton Antivirus, Telegram itself, Adobe Flash Player, KeePass) or a fabricated document such as an MRI scan result. Corporate targets whose devices are protected by enterprise security controls are frequently redirected toward less-defended personal devices. Once executed, CHOSEN BRICK/HEAVYGRAM establishes persistence via the HKCU Run registry key (observed values SMQDService and winappx), guards against re-infection using hardcoded mutexes (ytyjyujyu, noi672pp434awkc12f), and adds Microsoft Defender exclusions to reduce the likelihood its files are scanned or removed.
The implant collects screenshots, microphone audio, running-process and system information, email content, and WhatsApp/Telegram browser chat data, and can download additional payloads. Command and control is conducted through per-victim Telegram bots (a unique bot ID per infected machine, preventing cross-victim contamination), with newer variants relaying that Telegram traffic through commercial HTTPS/SOCKS5 proxy services (IPRoyal, LightningProxies) to obscure the C2 channel; stolen data is also exfiltrated to legitimate cloud object-storage services (Backblaze B2, Vultr Object Storage, Storj). At least one observed variant carries a full data-wipe capability, giving operators a destructive option against journalists' and activists' devices in addition to ongoing surveillance.
MITRE ATT&CK techniques used in TL-2026-2543
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114.001 Local Email Collection; T1123 Audio Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1090.002 External Proxy; T1102.002 Bidirectional Communication
Execution
Defense Evasion
Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
T1566.003 Spearphishing via Service
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Resource Development
T1585.001 Social Media Accounts
Reconnaissance
T1589 Gather Victim Identity Information
defense-impairment
Affected products and versions in Iranian State Actors Deploy CHOSEN BRICK Windows Malware to
- Microsoft — Windows
Vulnerable versions: All supported Windows versions (malware is delivered via social engineering, not a software vulnerability)
Remediation for Iranian State Actors Deploy CHOSEN BRICK Windows Malware to
Immediate actions
- Search endpoint logs and the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key for the reported values SMQDService and winappx
- Search for the reported mutexes ytyjyujyu and noi672pp434awkc12f as execution-guardrail indicators of infection
- Review Microsoft Defender exclusion lists for unexpected entries, particularly paths resembling C:\Windows \SysWOW64 (note the inserted space)
- Monitor or restrict egress to backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net where not business-required
- Report suspected compromises to national authorities: UK report.ncsc.gov.uk, US FBI IC3 (ic3.gov), Netherlands AIVD
Workarounds
- Do not install software received via links or attachments sent over WhatsApp or Telegram; install only from official app stores or vendor sites
- Do not disable SmartScreen or antivirus warnings when prompted during software installation
- Keep operating systems and applications configured for automatic updates
Longer-term hardening
- Deploy phishing-resistant MFA for at-risk individuals such as journalists, activists, and dissidents
- Enable application allowlisting and endpoint monitoring to flag unauthorized Registry Run-key modifications and new Defender exclusions
- Provide social-engineering awareness training focused on WhatsApp/Telegram impersonation of trusted contacts and IT support staff
- Segment and separately monitor personal devices used by high-risk individuals who also hold corporate access
Timeline of Iranian State Actors Deploy CHOSEN BRICK Windows Malware to
- FBI begins tracking a malware family later publicly named HEAVYGRAM (NCSC designation: CHOSEN BRICK), with the earliest linked activity dating to autumn 2023.
- Iranian state actors observed deploying CHOSEN BRICK/HEAVYGRAM against dissidents, activists, and journalists in the US, UK, and Netherlands, per the joint advisory's documented 'at least 2025' activity window.
- Advisory discloses that newer CHOSEN BRICK/HEAVYGRAM variants route Telegram C2 traffic through commercial HTTPS/SOCKS5 proxy services (IPRoyal, LightningProxies) to obscure communications.
- Advisory documents the full attack chain: WhatsApp/Telegram rapport-building, delivery of trojanized apps or fraudulent MRI documents, HKCU registry Run-key persistence, Microsoft Defender exclusion abuse, per-victim Telegram-bot C2, and screenshot/audio/email/browser-chat collection culminating in optional additional-payload download or full data wipe.
- UK NCSC, US FBI (via IC3 CSA 260915-2), and Netherlands AIVD jointly publish an advisory attributing CHOSEN BRICK/HEAVYGRAM to Iran's Ministry of Intelligence and Security (MOIS), detailing TTPs, IOCs, and mitigations.
- BleepingComputer, SecurityWeek, The Hacker News, Infosecurity Magazine, and other outlets report on the joint advisory, amplifying public awareness of the campaign.
- FBI publicly attributes HEAVYGRAM operations to Iran's MOIS, stating the tool is used to collect intelligence, conduct data leaks, and inflict reputational harm against regime-perceived opponents.
Sources cited for Iranian State Actors Deploy CHOSEN BRICK Windows Malware to
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
- US, UK, Dutch Agencies Expose Iranian 'Chosen Brick' Surveillance Malware
- Iranian cyber targeting of dissidents, activists and journalists
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
- Joint Cybersecurity Advisory: Iranian State Actor Use of CHOSEN BRICK / HEAVYGRAM Malware (IC3 CSA 260915-2)
- Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
- CHOSEN BRICK Malware Lets Iranian State Hackers Steal Emails, WhatsApp and Telegram Data
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
- NCSC and Allies Warn of Iranian Spyware Campaign
- FBI Details Iranian HEAVYGRAM Malware Campaign Targeting Dissidents and Journalists
More in malware
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies
Detection coverage for TL-2026-2543
As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2543 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.