Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.
The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate the microphone to record audio.
The FBI calls it HEAVYGRAM, and the U.K.’s National Cyber Security Center (NCSC) calls it CHOSEN BRICK.
The joint advisory was published on September 15 by the NCSC, the FBI, and the Netherlands’ intelligence service, the AIVD. The FBI also released an updated analysis of the malware that expands on a March 2026 alert, the first to describe the campaign, with more technical detail and new indicators of compromise.
The FBI attributes the malware to Iran’s Ministry of Intelligence and Security (MOIS), the country’s main intelligence agency, and dates the wider campaign to the autumn of 2023. The advisory says CHOSEN BRICK has been used against people in the U.K., the U.S., and the Netherlands, and around the world, since at least 2025.
The targets are mainly Iranian dissidents, journalists who oppose Iran, activists, and members of groups whose views clash with the government, the agencies say. But the FBI has warned that anyone Iran considers of interest could be a target.
The agencies say the danger goes beyond stolen data. Screenshots and other collected information can show a target’s contacts, location, and daily routine. The personal details of some victims have appeared on pro-Iranian leak sites, which the advisory says can increase the risk to their safety.
In March, the U.S. Justice Department seized four such Iranian leak sites, which it said had been used to post stolen data and to call for the killing of dissidents, journalists, and others.
Iran almost certainly uses this kind of cyber activity to help suppress those it sees as a threat, the agencies say. In some cases, they add, its intelligence services have plotted to kidnap or kill such people abroad.
How the Attack Works
The attack begins with a message. The attackers pose as someone the target knows or as tech support for a messaging app, building trust before sending a file that appears to be a legitimate program, the agencies say.
The attackers often start on a target’s work computer, the agencies say. If that does not succeed, they try to move to a personal device, which company security does not protect.
Reported disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, and Adobe Flash Player. In some cases, the file was made to look like MRI scan results.
When the target opens the file, a convincing fake screen appears while the real malware installs in the background. A first stage poses as the app, and a second stage connects the computer to a Telegram bot that the attackers use to control it and collect stolen data. Every version seen so far runs only on Windows.
To survive a restart, the malware adds itself to a Windows registry “Run” key, so it starts again each time the user logs in. It also tells Microsoft Defender, the built-in antivirus, to skip certain folders so its files are not scanned.
Each infected computer is given its own Telegram bot, which the agencies say keeps one victim’s activity from mixing with another’s.
Once running, the malware can be told to do many things: list running programs, take screenshots, turn on the microphone, copy Telegram and WhatsApp data from the browser, steal saved passwords and email addresses, download additional malware, and delete files. At least one version can also wipe the computer, according to the joint advisory.
The agencies say the malware has not been seen spreading across a network on its own, though it can download more tools. Stolen files leave the computer through the Telegram bot and through cloud storage services such as Vultr and Storj. Newer versions send their Telegram traffic through proxy servers to hide it, the advisory says.
Signs to Look For
The advisories list signs that defenders and at-risk users can check for, including:
- Registry key: a “Run” key entry named SMQDService or winappx, added so the malware starts at login.
- File path: a folder with an added space, C:\Windows \SysWOW64, where the malware drops extra files.
- Network: unexpected connections to otherwise-legitimate services, including api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net.
- Mutex: name markers the malware sets to avoid running twice, such as ytyjyujyu and noi672pp434awkc12f.
The FBI’s analysis and the joint advisory contain the full list, including file hashes. The agencies warn that the malware’s file names and folders can change, so these signs should not be treated as the only ones to watch for.
How to Protect Yourself
To lower the risk, the agencies recommend that individuals:
- Do not open files sent through messages or links, and download software only from official websites or app stores.
- Keep the operating system and all apps up to date, ideally with automatic updates.
- Run antivirus software and keep it switched on and current.
- Do not ignore SmartScreen warnings when downloading files.
They advise network administrators to:
- Turn on phishing-resistant multi-factor authentication.
- Use application allowlisting and managed-device controls.
- Use the scanning and security tools their email provider offers.
- Monitor computers and network traffic, and search logs for the indicators above.
Anyone who suspects an infection should check the “Run” key described above, tell their IT support, and report it to their national cyber agency. The advisories do not say whether removing the malware alone clears a compromise.
When the FBI first warned about the campaign in March, Telegram told TechCrunch that its moderators “routinely remove any accounts found to be involved with malware.” The agencies present their conclusions as assessments rather than as matters settled in court.




