U.S., U.K., and Dutch cybersecurity agencies have issued a joint advisory revealing a wide-ranging Iranian malware campaign known as HEAVYGRAM by the FBI and CHOSEN BRICK by the UK’s NCSC. Targeting dissidents, journalists, and activists globally, this malware masquerades as trusted software and is controlled via Telegram. It can exfiltrate emails and chats, capture screenshots, and record audio to monitor its victims. Earlier indicators first surfaced in March 2026, but recent tools and methods show a more expansive and persistent threat.
How the Malware Operates
The campaign—linked to Iran’s Ministry of Intelligence and Security—has been active since fall 2023, affecting victims in the U.S., U.K., the Netherlands, and elsewhere. It begins with social engineering: messages impersonating acquaintances or appearing as tech-support senders deliver files disguised as legitimate programs. Some of the impostor software names seen include Pictory, KeePass, Telegram, RunwayML, Norton, Adobe Flash Player, and even MRI scan results to exploit trust. Victims who run the file see a convincing fake interface while the genuine malware begins to install in the background. Once installed, the compromise spans two stages: first posing as a benign app, then setting up a Telegram bot for remote control.
Capabilities and Threat Pattern
Designed exclusively for Windows systems thus far, the malware makes itself persistent via registry key additions (“Run” key) and instructs Microsoft Defender to ignore its folders. Analysis shows it has full spy capabilities: extracting saved passwords from browsers, stealing Telegram and WhatsApp data, downloading additional payloads, deleting files, and notably, activating the microphone. Some versions even include functions to wipe entire machines. To avoid detection, newer iterations use Telegram traffic proxied via anonymizing services. Exfiltration channels include both Telegram bots and cloud storage platforms like Vultr and Storj.
Indicators & Defenses
Authorities recommend watching for a few telltale signs: registry entries under names like SMQDService or winappx that run at login; folders in paths like C:\Windows \SysWOW64with unusual spacing; unexpected connections to legitimate services like api.telegram.org, storjshare.io, and others; and unique mutex markers such as “ytyjyujyu”. Defenders should deploy multi-factor authentication resistant to phishing, enforce application allow-listing, keep operating systems and software fully updated, and not ignore warning prompts such as SmartScreen alerts. If compromised, victims are advised to involve IT support and national cyber agencies in removing the malware and assessing the breach.
This operation appears part of a larger Iranian strategy to suppress dissent abroad. The advisory also reiterates that stolen personal data has been published on pro-Iranian leak sites, sometimes accompanied by calls for violence. In March, U.S. authorities took down four such sites.
While the technical mechanisms—including Telegram-based control and fake-software lures—aren’t entirely novel, the scale and sophistication mark a concerning escalation. In depth tracking of HEAVYGRAM/CHOSEN BRICK shows persistent targeting, stealthy data exfiltration, and weaponization of online messaging infrastructure.
Analytically, this campaign underscores how nation-states are increasingly leveraging mainstream platforms and social engineering to carry out cyber espionage. For at-risk individuals—dissidents, journalists, and NGOs—the threat is no longer theoretical but active, with grave personal, professional, and security implications. What to watch closely: updates to Telegram’s bot policies, stronger detection tools for registry anomalies, and international cooperation to prosecute those behind such operations.