Personal safety and private lives are at stake for Iranian dissidents, journalists, activists and others the government considers "of interest" after a joint advisory says Tehran's intelligence service is using Telegram‑controlled Windows malware to spy on and expose targets worldwide.
Who issued the advisory and what they call the malware
On September 15, the U.K.'s National Cyber Security Center (NCSC), the U.S. Federal Bureau of Investigation (FBI), and the Netherlands' intelligence service (AIVD) published a joint advisory describing a Windows malware campaign. The FBI calls the malware HEAVYGRAM; the NCSC calls it CHOSEN BRICK. The FBI also released an updated analysis that expands on a March 2026 alert with additional technical detail and new indicators of compromise.
Targets, motive, and real‑world risk
The agencies attribute the malware to Iran's Ministry of Intelligence and Security (MOIS) and date the wider campaign to the autumn of 2023. CHOSEN BRICK has been used against people in the U.K., the U.S., the Netherlands, and elsewhere since at least 2025. The agencies say the primary targets are Iranian dissidents, journalists who oppose Iran, activists, and members of groups whose views clash with the government — but they warn that anyone Iran considers of interest could be targeted.
Beyond stolen documents, the advisory highlights how screenshots and other stolen data can reveal contacts, location and daily routines. Personal details from some victims have appeared on pro‑Iranian leak sites; the agencies say that public posting of stolen data can increase the risk to victims' safety. In March, the U.S. Justice Department seized four such Iranian leak sites that had been used to post stolen data and to call for the killing of dissidents, journalists, and others.
The agencies state that Iran almost certainly uses cyber activity of this kind to help suppress those it sees as a threat, and note that in some cases its intelligence services have plotted to kidnap or kill such people abroad. The advisory frames these findings as assessments rather than as matters settled in court.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow the attack unfolds and what the malware does
The attackers begin with a message, posing as someone the target knows or as tech support for a messaging app to build trust before sending a file that appears legitimate. The attackers often try a target's work computer first; if that fails they move to a personal device not protected by corporate security. Reported disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player, and even fabricated MRI scan results.
When opened, the file presents a convincing fake screen while installing the real malware in the background. A first stage masquerades as the app and a second stage connects the computer to a Telegram bot controlled by the attackers. Every version seen so far runs only on Windows. Each infected host is assigned its own Telegram bot to keep victims' data separate.
Capabilities the advisory lists include copying emails and chat messages, taking screenshots, activating the microphone to record audio, listing running programs, copying Telegram and WhatsApp data from the browser, stealing saved passwords and email addresses, downloading additional malware, deleting files, and — in at least one version — wiping the computer. The malware does not appear to spread across a network on its own, though it can download additional tools.
Technical indicators defenders should watch
- Registry Run key entries named SMQDService or winappx, added for persistence at login.
- A file drop folder using an added space: C:\Windows \SysWOW64 (note the space).
- Unexpected network connections to otherwise‑legitimate services, including api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net.
- Mutex markers such as ytyjyujyu and noi672pp434awkc12f used to prevent multiple instances.
Stolen files are exfiltrated through the per‑victim Telegram bots and through cloud storage services such as Vultr and Storj. Newer malware versions route Telegram traffic through proxy servers to obscure communications. The FBI's analysis and the joint advisory contain fuller lists and file hashes; the agencies caution that file names and folders can change and these indicators should not be treated as exhaustive.
How individuals and network administrators are advised to respond
The agencies give practical steps. For individuals: do not open files sent in messages or links, download software only from official sites or app stores, keep operating systems and apps up to date (ideally with automatic updates), run antivirus and keep it current, and heed SmartScreen warnings when downloading files. For network administrators: enable phishing‑resistant multi‑factor authentication, use application allowlisting and managed‑device controls, use your email provider's scanning and security tools, monitor computers and network traffic, and search logs for the indicators above.
Anyone who suspects an infection should check the Run key entries described, tell their IT support, and report the incident to their national cyber agency. The advisories do not say whether removing the malware alone clears a compromise. When the FBI first warned about the campaign in March, Telegram told TechCrunch that its moderators "routinely remove any accounts found to be involved with malware."
As the agencies lay out the technical trail from a deceptive message to a Telegram‑linked bot and to cloud storage, the tangible question left by their guidance is immediate and concrete: when a device is cleaned, have adversaries already used the stolen data to put a target at ongoing risk, and how should responders and national authorities address that continuing danger?




