Dev iconDevSep 27, 2026 ~1 min source read

Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Iranian Spyware That Reports Through Telegram On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on Windows spyware linked to Iranian intelligence. The advisory states that the tooling has been in use since at least 2025, with the wider campaign dating to autumn 2023.

Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram

Share this story

Send the public story page.

Useful takeaways from this story.

Iranian Spyware That Reports Through Telegram On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on Windows spyware linked to Iranian...

Capabilities and what to hunt The advisory lists program enumeration, screenshot capture, microphone recording, collection of Telegram and WhatsApp data, extraction of browser-stored passwords and email,...

The advisory states that the tooling has been in use since at least 2025, with the wider campaign dating to autumn 2023.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Iranian Spyware That Reports Through Telegram On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on Windows spyware linked to Iranian intelligence. The advisory states that the tooling has been in use since at least 2025, with the wider campaign dating to autumn 2023. Delivery and staging The operators approach targets through WhatsApp and Telegram while impersonating an acquaintance or someone offering technical support.

How it works

  • Documented mutexes and network indicators include api.telegram.org, vultrobjects.com, storjshare.io, shturl.cc, and commercial prox...
  • Capabilities and what to hunt The advisory lists program enumeration, screenshot capture, microphone recording, collection of Telegram and WhatsApp data, extraction of browser-stored passwords and email,...
  • The loader runs in two stages behind a convincing graphical interface, so the victim sees something that looks like a legitimate installer while the payload unpacks.
  • Once installed, the implant reports to a per-victim Telegram bot that acts as command and control.
  • Telegram is a legitimate service with valid certificates, so blocking it outright carries a cost, and the bot channel blends into ordinary encrypted traffic.

What to take from it

Exfiltration uses the same channel alongside Vultr object storage, Storj and Backblaze B2. Persistence is documented through registry Run keys, and the implant also adds Defender folder exclusions to protect itself. Investigators have noted a hidden SysWOW64 directory whose name carries a trailing space, a detail worth adding to endpoint hunting queries.

Details worth keeping

The two families are tracked as Chosen Brick and HEAVYGRAM. They send a file and ask the victim to run it. There is no self-propagation, so spread depends on social engineering.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app