Cybersecurity agencies in the United States, United Kingdom, and Netherlands have exposed a Windows malware that Iran's intelligence service deploys to surveil dissidents, journalists, and activists globally. The joint advisory, published September 15 by the U.K.'s National Cyber Security Centre, the FBI, and the Netherlands' intelligence service AIVD, reveals that the malware operates through Telegram's messaging platform and can capture emails, chat messages, screenshots, and audio recordings. The FBI calls the tool HEAVYGRAM, while the NCSC refers to it as CHOSEN BRICK.

The FBI attributes the malware to Iran's Ministry of Intelligence and Security and traces the broader campaign back to autumn 2023. CHOSEN BRICK has targeted people in the U.K., U.S., and Netherlands, as well as around the world, since at least 2025. The victims are predominantly Iranian dissidents, journalists critical of Iran, activists, and members of organizations whose beliefs conflict with the government. The agencies warn that anyone Iran deems interesting could become a target. Screenshots and other harvested information can reveal a target's contacts, whereabouts, and daily patterns. Personal details of some victims have surfaced on pro-Iranian leak sites, which the advisory notes can heighten risks to their physical safety. In March, the U.S. Justice Department confiscated four Iranian leak sites that had been used to publish stolen data and to advocate for killing dissidents, journalists, and others.

The assault begins with a message, with attackers impersonating someone the target knows or tech support for a messaging app to establish trust before delivering a file disguised as legitimate software. Reported disguises include the AI video app Pictory, password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player, and in some instances, MRI scan results. When the target launches the file, a convincing fake interface appears while the actual malware installs behind the scenes. A first stage mimics the app, and a second stage links the computer to a Telegram bot that attackers use for control and data collection. Every version observed runs exclusively on Windows. To persist through restarts, the malware inserts itself into a Windows registry "Run" key and instructs Microsoft Defender to ignore certain folders. Each infected computer receives its own Telegram bot, which the agencies say prevents one victim's activity from blending with another's. Once active, the malware can list running programs, capture screenshots, activate the microphone, copy Telegram and WhatsApp data from browsers, steal saved passwords and email addresses, download additional malware, delete files, and in at least one version, wipe the entire computer.

The agencies say Iran almost certainly uses this type of cyber activity to help suppress those it views as threats, and in some cases, its intelligence services have plotted to kidnap or kill such individuals abroad. The advisory lists indicators defenders can check for, including a "Run" key entry named SMQDService or winappx, a folder with an added space at C:\Windows \SysWOW64, unexpected connections to api.telegram.org and cloud storage services like Vultr and Storj, and mutex markers such as ytyjyujyu. To reduce risk, the agencies recommend individuals avoid opening files sent through messages, download software only from official sources, keep systems updated, run current antivirus software, and not ignore SmartScreen warnings. Network administrators should enable phishing-resistant multi-factor authentication, use application allowlisting, leverage email security tools, and monitor network traffic for the indicators above. When the FBI first alerted about the campaign in March, Telegram told TechCrunch that its moderators "routinely remove any accounts found to be involved with malware." Organizations facing sophisticated nation-state threats may need to reassess whether convenience features like bot integrations justify the operational risk they introduce, particularly when adversaries repurpose legitimate communication platforms as command-and-control infrastructure.