Cybersecurity authorities in the United States, the United Kingdom, and the Netherlands have issued a high-priority alert regarding a persistent and sophisticated Windows-based malware campaign orchestrated by Iranian state-sponsored actors. The coordinated warning, released on September 15, highlights a multi-year effort by the Iranian Ministry of Intelligence and Security (MOIS) to surveil, compromise, and intimidate journalists, activists, and political dissidents across the globe.
The malware, identified by the FBI as HEAVYGRAM and referred to by the U.K.’s National Cyber Security Center (NCSC) as CHOSEN BRICK, utilizes the Telegram messaging platform as its primary command-and-control (C2) infrastructure. By exploiting the platform’s encrypted nature, the attackers maintain a stealthy communication channel to exfiltrate sensitive data, including private emails, browser-based chat logs, and financial credentials. Beyond simple data theft, the malware grants operators full remote access to a victim’s device, enabling real-time surveillance through microphone activation and high-resolution screen capturing.
Chronology of the Surveillance Campaign
The roots of this espionage operation can be traced back to the autumn of 2023, a period characterized by heightened geopolitical tensions and increased Iranian state efforts to monitor diaspora populations. While the initial technical analysis was disseminated in a March 2026 FBI alert, subsequent investigations by the NCSC and the Netherlands’ AIVD have revealed that the campaign is significantly broader than previously estimated.
By early 2025, intelligence suggests that the MOIS had successfully pivoted from regional monitoring to a global reach, targeting individuals in the U.K., the U.S., and throughout the European Union. The September 2026 joint advisory serves as an evolution of these findings, providing updated technical indicators of compromise (IOCs) and mapping the tactical shifts the Iranian threat actors have adopted to evade modern endpoint detection and response (EDR) systems.
Technical Anatomy of the Attack
The operational methodology employed by Iranian actors relies heavily on social engineering, a psychological approach to cyber-attacks that exploits the inherent trust between colleagues and the necessity of technical support in professional environments.
The attack chain typically begins with an initial lure, where threat actors masquerade as familiar associates or official support personnel from legitimate software providers. Once trust is established, the target is prompted to download a "utility" or "patch" file. These files are expertly disguised as reputable applications, including the password manager KeePass, the AI-driven video editor RunwayML, the video creation tool Pictory, or even common utilities like Adobe Flash Player and various antivirus packages.

Once the payload is executed, the malware functions in a two-stage process. The first stage presents a convincing, benign interface to the user—sometimes even simulating an MRI scan report or a legitimate software installation wizard—to prevent immediate suspicion. In the background, the second stage initiates a connection to a dedicated Telegram bot. This bot architecture is a critical feature of the campaign; by assigning a unique Telegram bot to every single infected machine, the attackers ensure that the data exfiltrated from one victim remains siloed, preventing potential cross-contamination of intelligence and complicating attribution efforts for security researchers.
To ensure persistence, the malware modifies the Windows Registry "Run" key, ensuring that the malicious code initiates automatically upon every system boot. Furthermore, the malware proactively instructs Microsoft Defender to ignore specific directory paths, effectively creating a "blind spot" in the operating system’s native security defense.
Implications for Digital Security and Human Rights
The danger posed by HEAVYGRAM and CHOSEN BRICK extends far beyond the technical loss of data. Security analysts emphasize that the real-world consequences for the victims are grave. By mapping a target’s daily routine, physical location, and interpersonal network, the Iranian intelligence services are able to facilitate physical intimidation.
In several documented instances, the personal information, contact lists, and private correspondence of dissidents have been published on pro-Iranian leak sites. These platforms serve a dual purpose: they act as a repository for stolen data and as a psychological weapon intended to silence opposition through the threat of public exposure or physical harm. The U.S. Department of Justice’s decision to seize four such domains in March 2026 underscored the extent of this state-sponsored psychological warfare, revealing that these sites were being used to issue explicit calls for violence against journalists and political activists.
Official Responses and International Cooperation
The joint advisory issued by the FBI, NCSC, and AIVD represents a rare level of international cooperation aimed at neutralizing a specific state-backed threat. By sharing technical signatures and behavioral patterns, these agencies hope to bolster the defenses of at-risk populations.
The FBI has urged individuals who believe they may be targets of such activity to remain vigilant against unsolicited communications, particularly those originating from unknown Telegram accounts or unexpected professional contacts. The agency emphasized that while the malware currently targets Windows environments, the underlying tactics of social engineering are platform-agnostic and could easily be adapted to mobile or Linux systems in future iterations.
Telegram, for its part, has stated in prior communications that it maintains strict policies against the use of its platform for malicious activity. "We routinely remove any accounts found to be involved with malware," a spokesperson for the platform noted following the initial March 2026 alerts. However, the modular and decentralized nature of bot-based C2 systems makes complete eradication difficult, leading security experts to call for more robust proactive scanning and stricter adherence to zero-trust architecture in sensitive environments.

Mitigating the Threat: A Defensive Framework
In light of these findings, cybersecurity experts recommend a multi-layered defense strategy for both individuals and organizations. For individual users, the most critical defensive measure remains the verification of file sources. Any software update or application download should be performed only through official, verified websites. Users are advised to avoid clicking links or downloading files from Telegram messages, even if the sender appears to be a known contact, as account hijacking is a common precursor to these attacks.
For network administrators and security teams, the following measures are strongly recommended:
- Registry Monitoring: Implement continuous monitoring for unauthorized modifications to the Windows "Run" keys, which are primary indicators of persistent malware.
- Endpoint Security Hardening: Ensure that all endpoint protection platforms are configured to prevent the modification of security settings, including the exclusion lists of Microsoft Defender.
- Network Segmentation: Restrict outbound traffic to known cloud storage providers and unauthorized messaging platforms, particularly from workstations handling sensitive communications.
- Traffic Analysis: Employ advanced network traffic analysis to detect irregular communication patterns with Telegram API endpoints, which may indicate command-and-control activity.
The Broader Geopolitical Context
The deployment of HEAVYGRAM/CHOSEN BRICK is symptomatic of a broader shift in the landscape of state-sponsored cyber-espionage. As nation-states increasingly outsource or automate parts of their intelligence-gathering operations, the barrier to entry for conducting sophisticated surveillance has lowered.
The use of public, encrypted messaging apps like Telegram to facilitate C2 communications is a tactical innovation that complicates traditional network-based detection. Because Telegram is a legitimate, widely used service, defenders cannot simply block the domain without significantly impacting legitimate business operations. This "dual-use" dilemma highlights the growing challenges faced by intelligence agencies in balancing user privacy with the need to interdict state-sponsored actors.
As of late 2026, the investigation remains ongoing. The intelligence community expects that Iranian actors will continue to iterate on these tools, potentially incorporating obfuscation techniques or expanding their targeting criteria. For the global community of journalists and activists, the message from the FBI and its international partners is clear: the digital environment is being actively weaponized, and the maintenance of operational security (OPSEC) is no longer a luxury, but a fundamental necessity for personal safety.
By standardizing reporting procedures and sharing real-time indicators of compromise, the tripartite alliance of the U.S., U.K., and Netherlands aims to disrupt the operational lifecycle of Iranian intelligence, forcing the state to expend greater resources to maintain its illicit surveillance networks. Whether these efforts will lead to a long-term reduction in such activity remains a subject of ongoing analysis by international security observers.
