International Cybersecurity Agencies Expose Sophisticated Iranian Malware Campaign Targeting Global Dissidents and Journalists

In a coordinated international security alert, cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have published comprehensive technical details regarding a sophisticated Windows-based malware operation. According to the joint advisory, the campaign is orchestrated by Iran’s Ministry of Intelligence and Security (MOIS) and utilizes the popular Telegram messaging application as a command-and-control (C2) infrastructure. The primary objective of this cyber espionage network is to infiltrate the digital perimeters of Iranian dissidents, investigative journalists, human rights activists, and political opposition members residing outside of Iran.
The malware, identified as HEAVYGRAM by the United States Federal Bureau of Investigation (FBI) and as CHOSEN BRICK by the United Kingdom’s National Cyber Security Center (NCSC), represents an evolving threat landscape where state-sponsored threat actors leverage consumer-grade, encrypted messaging applications to mask malicious communications. Alongside the FBI and the NCSC, the Dutch General Intelligence and Security Service (AIVD) contributed to the intelligence findings, emphasizing the cross-border nature of the digital surveillance operations.
As geopolitical tensions continue to intersect with cyberspace, intelligence officials warn that the implications of this campaign extend far beyond standard industrial espionage or intellectual property theft. For the targeted individuals—many of whom have fled persecution in Iran—a successful digital compromise directly translates to real-world physical danger, harassment, and targeted physical violence.
Chronology and Evolution of the Cyber Espionage Campaign
The origins of this state-sponsored surveillance operation trace back to the autumn of 2023, when threat intelligence researchers first began tracking anomalous activities targeting Persian-speaking diaspora communities. Initially operating with lower sophistication, the campaign matured steadily over the subsequent months, culminating in broader deployments across the United States, the United Kingdom, and the Netherlands by early 2025.
The timeline of official discoveries and governmental interventions underscores the escalating severity of the threat:

- Autumn 2023: Initial indicators of compromise linked to Iranian intelligence services are identified by threat researchers observing targeted phishing and social engineering directed at diaspora groups.
- March 2026: The FBI releases its first formal cyber alert warning organizations and individuals about government-backed Iranian cyber actors deploying Telegram-based command-and-control frameworks to push malware onto identified targets.
- March 2026: In a parallel enforcement action, the United States Department of Justice seizes four prominent pro-Iranian leak sites. Investigators reveal that these platforms were actively utilized not only to host exfiltrated data but also to publish direct incitement and calls for physical harm against specific dissidents and journalists.
- September 15, 2026: A comprehensive joint advisory is officially published by the NCSC, the FBI, and the AIVD. This release provides deeper forensic analysis, comprehensive indicators of compromise (IoCs), and distinct technical categorizations for the malware strains, officially dubbed HEAVYGRAM and CHOSEN BRICK.
Technical Architecture: How the HEAVYGRAM and CHOSEN BRICK Malware Operates
The attack vector typically begins with a calculated social engineering phase. Threat actors meticulously research their targets, often posing as trusted acquaintances, colleagues, or technical support representatives for prominent communication platforms. By establishing a veneer of trust through prolonged dialogue, the attackers manipulate the target into downloading a seemingly benign file.
If attackers initially encounter resistance on secure corporate or institutional networks, they frequently pivot their strategy toward personal devices, which lack enterprise-grade monitoring and endpoint detection solutions. The malicious payloads are routinely disguised as popular, legitimate software applications to bypass casual suspicion. Documented disguises include the AI video composition platform Pictory, the open-source password manager KeePass, legitimate installations of Telegram, video generation tools like RunwayML, mainstream antivirus programs such as Norton Antivirus, and legacy media frameworks like Adobe Flash Player. In particularly personalized attacks, malicious files have even been structured to mimic sensitive medical documentation, such as MRI scan results.
Upon execution, the attack sequence unfolds through a multi-stage process:
- Deceptive Interface: A convincing, authentic-looking graphical user interface mimicking the disguised application launches on the user’s screen, masking the background installation of the malicious payload.
- Persistence Mechanisms: To survive system reboots and user logouts, the malware modifies the Windows registry, embedding itself within the "Run" key to ensure automated execution upon every system startup.
- Defense Evasion: Advanced variants actively attempt to neutralize built-in security features, specifically instructing Microsoft Defender to exclude critical directories from routine antivirus scans, thereby shielding malicious files from detection.
- Command and Control (C2): The malware establishes a dedicated connection via a unique Telegram bot assigned to each infected machine. Newer iterations route this traffic through intermediary proxy servers to obscure the origin of the network requests. Data exfiltration and remote instructions are subsequently handled seamlessly through the messaging platform and secondary cloud storage repositories such as Vultr and Storj.
Once operational, the malware grants its handlers extensive capabilities. It can inventory running processes, capture high-resolution screenshots, covertly activate device microphones for ambient audio surveillance, harvest cached credentials from web browsers, and extract session data from applications like WhatsApp and Telegram. Furthermore, the toolkit possesses destructive capabilities, with select versions engineered to execute complete system wiping functions.
Official Responses and Industry Reactions
The disclosure of the HEAVYGRAM and CHOSEN BRICK campaigns has elicited strong responses from governmental bodies, intelligence agencies, and technology corporations alike. Western intelligence agencies have emphasized that these cyber operations are not isolated incidents of data collection, but rather an integrated component of a broader transnational repression strategy. According to security assessments from the participating nations, compromised digital profiles are frequently leveraged to feed intelligence into physical tracking, harassment, and, in severe cases, active kidnapping or assassination plots orchestrated abroad by Iranian intelligence operatives.
Technology platforms whose ecosystems have been inadvertently co-opted by state-sponsored actors have also faced intense scrutiny. Following the initial FBI warnings earlier in the year, representatives for Telegram publicly addressed the exploitation of their platform, noting that automated moderation systems and human security teams routinely investigate and ban accounts found to be facilitating malicious command-and-control operations. However, cybersecurity researchers point out that the decentralized and encrypted nature of messaging applications continues to present persistent challenges for rapid detection and mitigation.

Meanwhile, legal and regulatory authorities continue to dismantle the auxiliary infrastructure supporting these cyber campaigns. The Department of Justice’s seizure of Iranian-linked leak sites marked a critical blow to the psychological operations arm of the network, cutting off public forums used to intimidate targets by broadcasting their stolen private data.
Broader Implications for Global Cybersecurity and Human Rights
The public attribution of HEAVYGRAM and CHOSEN BRICK highlights a troubling evolution in modern cyber warfare: the increasing use of dual-use consumer applications by state actors to conduct targeted espionage against civil society. Traditionally, sophisticated custom malware frameworks were reserved for high-value geopolitical targets, critical infrastructure, and defense contractors. The deployment of Telegram-controlled malware against individual activists and journalists demonstrates a democratization of cyber espionage capabilities among authoritarian intelligence services.
For civil society organizations, human rights defenders, and independent media outlets operating globally, the advisory serves as a stark reminder of the asymmetrical risks digital connectivity presents. Dissidents living in Western democracies often assume a baseline of physical and digital safety that authoritarian states actively seek to puncture through remote surveillance.
Security experts stress that standard endpoint protection is insufficient without comprehensive digital hygiene and behavioral awareness. Individuals identified as high-risk targets are urged to implement rigorous security practices, including:
- Exercising extreme caution when receiving unsolicited files, even from known contacts whose accounts may have been compromised.
- Utilizing hardware security keys and multi-factor authentication (MFA) resistant to phishing.
- Regularly auditing system startup configurations, registry keys, and unexpected software exclusions within Windows security settings.
- Collaborating closely with specialized digital security organizations dedicated to protecting at-risk journalists and human rights defenders.
As intelligence agencies continue to monitor the infrastructure associated with the MOIS cyber units, the international community faces ongoing challenges in holding state-sponsored threat actors accountable for transnational digital repression. The collaborative reporting by the FBI, NCSC, and AIVD marks an essential step toward transparency, equipping defenders worldwide with the technical indicators necessary to identify, isolate, and neutralize these persistent espionage campaigns.







