International Cybersecurity Coalition Exposes Iranian State-Sponsored Spyware Campaign Targeting Dissidents and Journalists Worldwide

In a coordinated international disclosure, cybersecurity and intelligence agencies from the United States, the United Kingdom, and the Netherlands have released comprehensive technical disclosures regarding an advanced Windows-based malware strain deployed by Iranian state-sponsored actors. The surveillance apparatus, identified by the United States Federal Bureau of Investigation (FBI) as HEAVYGRAM and by the United Kingdom’s National Cyber Security Center (NCSC) as CHOSEN BRICK, is actively utilized by the Iranian Ministry of Intelligence and Security (MOIS). Designed to compromise high-profile targets across multiple continents, the espionage operation specifically zeroes in on political dissidents, investigative journalists, human rights activists, and individuals deemed adversarial to the Tehran regime.
The joint advisory, published on September 15, consolidates findings from the NCSC, the FBI, and the Dutch General Intelligence and Security Service (AIVD). It builds extensively upon earlier warnings issued by American authorities in March 2026, providing deeper technical indicators of compromise (IoCs), behavioral analyses, and mitigation strategies. According to intelligence assessments, while the broader digital intrusion campaign originated as early as the autumn of 2023, the deployment of the CHOSEN BRICK framework against international targets has accelerated significantly since at least 2025.
Anatomy of the HEAVYGRAM and CHOSEN BRICK Malware
HEAVYGRAM and CHOSEN BRICK represent a sophisticated evolution in targeted cyber espionage. Operating exclusively within Windows environments, the multi-stage malware is engineered to harvest sensitive data quietly while maintaining persistent access to infected endpoints.
The intrusion vector invariably relies on social engineering. Threat actors initiate contact by posing as trusted acquaintances, professional associates, or technical support representatives for popular communication platforms. By establishing a veneer of legitimacy, the operators manipulate targets into downloading and executing seemingly benign files. These malicious payloads are frequently disguised as popular software applications and productivity tools, including the AI video generation platforms Pictory and RunwayML, the password manager KeePass, legitimate messaging clients like Telegram, enterprise security solutions such as Norton Antivirus, and Adobe Flash Player. In several documented instances, the malicious file was crafted to masquerade as medical diagnostics, specifically MRI scan results, to lower the victim’s skepticism.
Upon execution, the malware deploys a dual-layered mechanism. The first stage presents a convincing decoy application to distract the user, while the second stage silently installs the core operational modules in the background. To achieve persistence across system reboots, the malware embeds itself into the Windows registry under the "Run" key, ensuring execution upon every user login. Furthermore, the payload dynamically interacts with native security defenses, instructing Microsoft Defender to exclude specific directories from routine scans to evade detection.

A defining characteristic of HEAVYGRAM is its command-and-control (C2) architecture, which leverages the Telegram messaging application. Every compromised workstation is assigned a dedicated Telegram bot, compartmentalizing the victim pool and preventing operational cross-contamination. Newer iterations of the malware further obfuscate their network footprint by routing all Telegram communications through intermediary proxy servers. Exfiltrated data and secondary payloads move seamlessly through the Telegram infrastructure alongside cloud storage providers such as Vultr and Storj.
Capabilities and Operational Impact
Once established on a target machine, the spyware grants operators extensive surveillance capabilities. The malware can execute comprehensive system reconnaissance, inventory running processes, capture high-resolution screenshots, and surreptitiously activate system microphones to record ambient audio. Furthermore, it targets browser environments to extract cached credentials, session cookies, and stored data from encrypted communication applications like Telegram and WhatsApp. In its most destructive configurations, the malware possesses wipe functionalities capable of permanently erasing system files or rendering the host machine inoperable.
Beyond digital data theft, intelligence agencies emphasize that the implications of the HEAVYGRAM campaign extend into physical security threats. Screenshots and harvested metadata frequently capture precise geolocation details, daily routines, and vulnerable personal networks. In numerous cases, this purloined information has surfaced on pro-Iranian leak sites designed to intimidate dissidents and publicly expose their private lives.
The operational synergy between digital espionage and physical targeting underscores a broader state strategy. Western security agencies note that cyberspace operations conducted by the MOIS frequently serve as precursors to kinetic harassment, transnational repression, and, in severe instances, physical plots orchestrated abroad to kidnap or assassinate regime critics.
Chronology of the Espionage Campaign
The public exposure of HEAVYGRAM represents the culmination of a multi-year investigative effort by international law enforcement and intelligence entities:
- Autumn 2023: Intelligence assessments indicate the inception of the broader MOIS-backed cyber campaign, characterized by initial tool development and preliminary reconnaissance against regional targets.
- Throughout 2024: Attackers refine their social engineering tactics, broadening their scope to encompass Western jurisdictions and testing various software disguises to maximize installation success.
- 2025: Operational deployment of CHOSEN BRICK expands globally, systematically targeting dissidents, journalists, and activists residing within the United States, the United Kingdom, the Netherlands, and other allied nations.
- March 2026: The FBI issues its initial public alert warning of Iranian cyber actors utilizing Telegram-based command-and-control infrastructures to deploy malware against specific targets. Concurrently, the U.S. Department of Justice executes legal actions to seize four Iranian-linked leak sites utilized for psychological operations and data publication.
- September 15, 2026: The NCSC, FBI, and AIVD publish a joint advisory alongside updated technical analyses detailing HEAVYGRAM and CHOSEN BRICK, offering comprehensive indicators of compromise to assist global defenders.
Official Responses and Industry Action
The collaborative disclosure underscores an unprecedented level of intelligence sharing among Western allies aimed at disrupting state-sponsored transnational repression. Government agencies have urged civil society organizations, media outlets, and high-risk individuals to heighten their operational security postures.

In response to previous revelations regarding the misuse of its platform for malware C2 operations, Telegram representatives reiterated their commitment to platform integrity. Corporate statements emphasized that moderation teams continuously monitor and purge accounts identified as participating in malicious activities or cyberattacks. However, security analysts note that the decentralized and automated nature of Telegram bots presents ongoing challenges for platform administrators seeking to eradicate abuse entirely.
Mitigation and Defense Recommendations
To counter the threat posed by HEAVYGRAM and similar state-sponsored spyware, cybersecurity authorities have issued prescriptive guidance for both individual users and enterprise network administrators.
For individuals—particularly those identified as high-risk due to their activism, journalism, or political affiliations—recommendations include exercising extreme vigilance regarding unsolicited file transfers, verifying the authenticity of software downloads through official vendor channels, and deploying robust endpoint detection tools. Users are advised to routinely audit their Windows registry keys for unauthorized entries under the "Run" path and to utilize multi-factor authentication (MFA) secured by hardware tokens where possible.
Enterprise network administrators are encouraged to monitor network traffic for anomalous outbound connections directed toward cloud storage providers and Telegram API endpoints. Defenders should implement rigorous application whitelisting, restrict execution privileges for standard user accounts, and ensure that built-in security solutions are configured to log and alert on registry modifications associated with persistence mechanisms.
Individuals who suspect compromise are strongly advised to isolate affected hardware immediately, notify internal IT support structures, and report the incident to their respective national cybersecurity authorities. While technical remediation can remove known payloads, intelligence agencies caution that the full scope of compromised credentials requires a comprehensive password reset and security overhaul across all personal and professional accounts.







