Iran's intelligence service is running a malware campaign that targets dissidents, journalists, and activists around the world. And they're using Telegram to control it.
The FBI calls the malware HEAVYGRAM. The UK's National Cyber Security Centre calls it CHOSEN BRICK. Same thing, different names.
The joint advisory came out on September 15. It was published by the NCSC, the FBI, and the Netherlands' AIVD. The FBI also released an updated technical analysis that expands on a warning from March 2026.
Let me break down what's happening.
Quick Summary
|
What |
Details |
|
Malware |
HEAVYGRAM (FBI) / CHOSEN BRICK (NCSC) |
|
Attribution |
Iran's Ministry of Intelligence and Security |
|
C2 |
Telegram bots |
|
Targets |
Dissidents, journalists, activists |
|
Active since |
Autumn 2023 |
|
Platform |
Windows only |
Who's Behind It
The FBI attributes the malware to Iran's Ministry of Intelligence and Security - MOIS. That's the country's main intelligence agency.
The campaign dates back to autumn 2023. The advisory says CHOSEN BRICK has been used against people in the UK, the US, the Netherlands, and elsewhere since at least 2025.
Who are the targets?
Mainly Iranian dissidents. Journalists who oppose the government. Activists. Members of groups whose views clash with Tehran.
But the FBI warns that anyone Iran considers "of interest" could be a target. That's a broad net.
Why This Is More Than Just Data Theft
The agencies say the danger goes beyond stolen information.
Screenshots and other collected data can reveal a target's contacts, their location, and their daily routine. That's pattern-of-life intelligence. It can be used to track someone, threaten them, or worse.
The personal details of some victims have appeared on pro-Iranian leak sites. The advisory says that can increase the risk to their safety.
In March, the US Justice Department seized four Iranian leak sites. Those sites had been used to post stolen data and to call for the killing of dissidents, journalists, and others.
Iran almost certainly uses this kind of cyber activity to help suppress people it sees as a threat, the agencies say. In some cases, its intelligence services have plotted to kidnap or kill such people abroad.
How the Attack Works
It starts with a message.
The attackers pose as someone the target knows. Or as tech support for a messaging app. They build trust. Then they send a file that looks like a legitimate program.
Common disguises:
|
Disguise |
What It Pretends to Be |
|
Pictory |
AI video app |
|
KeePass |
Password manager |
|
Telegram |
Messaging app |
|
RunwayML |
AI video tool |
|
Norton Antivirus |
Security software |
|
Adobe Flash Player |
Legacy media player |
|
MRI scan results |
Medical document |
The attackers often start on a target's work computer. If that doesn't work, they try to move to a personal device. Personal devices don't have company security protection.
When the target opens the file, a convincing fake screen appears. The real malware installs in the background.
Two stages:
- First stage poses as the app.
- Second stage connects the computer to a Telegram bot.
Every version seen so far runs only on Windows.
How It Stays Hidden
The malware does two things to survive.
- Registry Run key. It adds itself to a Windows "Run" key. That means it starts again every time the user logs in.
- Defender exclusions. It tells Microsoft Defender, the built-in antivirus, to skip certain folders. That way its files don't get scanned.
Each infected computer gets its own Telegram bot. The agencies say that keeps one victim's activity from mixing with another's.
What the Malware Can Do
Once it's running, the attackers can tell it to do a lot.
- List running programs
- Take screenshots
- Turn on the microphone and record audio
- Copy Telegram and WhatsApp data from the browser
- Steal saved passwords and email addresses
- Download additional malware
- Delete files
- Wipe the computer (at least one version can do this)
The malware doesn't spread across a network on its own. But it can download more tools.
Stolen files leave the computer through the Telegram bot and through cloud storage services like Vultr and Storj. Newer versions route their Telegram traffic through proxy servers to hide it.
Signs to Look For
The advisory lists indicators of compromise. Here's what to check.
- Registry key: Look for a Run key entry named SMQDService or winappx.
- File paths: Search for a folder having an additional space character in it: C:\Windows\SysWOW64. This is where the malware creates its additional files.
- Connections to networks: Be on guard for any suspicious connections to the following:
- api.telegram.org
- vultrobjects.com
- storjshare.io
- backblazeb2.com
- iproyal.com
- lightningproxies.net
- Mutexes: The malware sets markers to avoid running twice. Look for names like ytyjyujyu and noi672pp434awkc12f.
The FBI's analysis has the full list, including file hashes. But the agencies warn that file names and folders can change. Don't rely on these indicators alone.
How to Protect Yourself
For individuals:
- Don't open files sent through messages or links.
- Download all software from official sources or legitimate app stores.
- Update your operating system and apps regularly. Use auto-updates.
- Run antivirus software. Keep it on and current.
- Don't ignore SmartScreen warnings.
For network administrators:
- Turn on phishing-resistant multi-factor authentication.
- Use application allowlisting and managed-device controls.
- Use the scanning and security tools your email provider offers.
- Monitor computers and network traffic.
- Search logs for the indicators above.
If you suspect an infection, check the Run key. Tell your IT support. Report it to your national cyber agency.
The advisories don't say whether removing the malware alone clears a compromise. That's an important gap.
The Telegram Response
When the FBI first warned about this campaign in March, Telegram told TechCrunch that its moderators "routinely remove any accounts found to be involved with malware."
The agencies present their conclusions as assessments. Not as matters settled in court.
The Bottom Line
Iran's intelligence service is using HEAVYGRAM to spy on dissidents, journalists, and activists. The malware is controlled through Telegram. It can steal emails, chats, screenshots, and audio. It can wipe your computer. The US, UK, and Netherlands issued a joint advisory. Check your systems for the indicators. Protect yourself.
Quick Reference:
|
Key Point |
Detail |
|
Malware |
HEAVYGRAM / CHOSEN BRICK |
|
Attribution |
Iran MOIS |
|
C2 |
Telegram bots |
|
Targets |
Dissidents, journalists, activists |
|
Platform |
Windows only |
|
Active since |
Autumn 2023 |
What to Do:
- Don't open files from messages
- Keep everything updated
- Run antivirus
- Check for Run key entries
- Monitor network connections
- Report suspected infections
FAQ Section
What is HEAVYGRAM?
Malware targeting Windows, used by the Ministry of Intelligence and Security of Iran to monitor dissidents, journalists, and activists. Controlled via Telegram.
How does it spread?
Attackers pose as someone the target knows or as tech support. They send a file that looks legitimate. When opened, a fake screen appears while the malware installs.
What can it do?
Screenshots, audio recordings, emails, chats, password thefts, malware downloads, and wiping of the computer will be conducted.
How do I know if I'm infected?
Check for Run key entries named SMQDService or winappx. Look for the folder C:\Windows \SysWOW64. Watch for connections to api.telegram.org and other listed services.
What should I do if I suspect infection?
Check the Run key. Tell your IT support. Report it to your national cyber agency.