Executive Summary
Since autumn 2023, Iran's Ministry of Intelligence and Security (MOIS) has deployed sophisticated malware called HEAVYGRAM (FBI designation) or CHOSEN BRICK (UK NCSC designation) to conduct extensive cyber espionage operations targeting Iranian dissidents, journalists, and activists worldwide. The Windows-based malware uses Telegram messaging app for command and control, enabling attackers to steal emails, capture screenshots, record audio through microphones, and exfiltrate sensitive communications. Victims are initially compromised through social engineering tactics where attackers impersonate trusted contacts or technical support, delivering malicious files disguised as legitimate applications like Adobe Flash, Norton Antivirus, or even medical scan results.
This campaign represents a significant escalation in state-sponsored surveillance capabilities, demonstrating how authoritarian regimes are weaponizing popular communication platforms for transnational repression. The targeting extends beyond digital espionage, with stolen personal information being published on Iranian leak sites to endanger victims' physical safety, highlighting the intersection of cyber operations with traditional intelligence gathering and intimidation tactics.
Why This Matters Now
Nation-state actors are increasingly leveraging legitimate communication platforms like Telegram for covert operations, making detection more challenging while expanding surveillance capabilities against diaspora communities and dissidents globally.
Attack Path Analysis
Iranian MOIS operators conducted a targeted cyber espionage campaign using HEAVYGRAM/CHOSEN BRICK malware, beginning with social engineering to deliver fake applications via messaging platforms. After establishing initial access on Windows systems, the malware achieved persistence through registry modifications and defender exclusions. The attack leveraged Telegram bots for command and control while exfiltrating sensitive data through cloud storage services, ultimately enabling surveillance and intelligence collection against dissidents and journalists worldwide.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers posed as trusted contacts or tech support to deliver malicious files disguised as legitimate applications (Pictory, KeePass, Telegram, Norton) through messaging platforms, targeting work computers initially before pivoting to personal devices
MITRE ATT&CK® Techniques
Spearphishing Attachment
Windows Command Shell
Registry Run Keys / Startup Folder
Disable or Modify Tools
Web Protocols
Screen Capture
Audio Capture
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(a)
NIS2 Directive – Risk analysis and information system security policies
Control ID: Art. 21(2)(a)
DORA – ICT risk management framework
Control ID: Art. 11(1)
PCI DSS 4.0 – Software engineering techniques for developing secure software
Control ID: 6.4.2
ISO 27001:2022 – Filtering of web content
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Newspapers/Journalism
Iranian MOIS targets journalists opposing Iran with Telegram-controlled malware enabling surveillance, data theft, and location tracking, severely compromising source protection and editorial independence.
Civic/Social Organization
Dissidents and activists face targeted espionage through Windows malware with screenshot capabilities and audio recording, exposing organizational communications and endangering member safety worldwide.
Government Administration
Government personnel handling sensitive communications are vulnerable to credential theft and surveillance through sophisticated malware disguised as legitimate applications, compromising national security operations.
Legal Services
Legal professionals representing dissidents or handling sensitive cases face malware attacks that steal client communications and expose confidential attorney-client privileged information to foreign intelligence.
Sources
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalistshttps://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.htmlVerified
- Iranian Cyber Targeting of Dissidents, Activists and Journalistshttps://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalistsVerified
- FBI Cyber Security Advisory - Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targetshttps://www.ic3.gov/CSA/2026/260915.pdfVerified
- Justice Department Disrupts Iranian Cyber-Enabled Psychological Operationshttps://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operationsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this Iranian espionage campaign by limiting malware communication paths and reducing blast radius through network segmentation and controlled egress enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric would likely have limited the initial malware's ability to establish broader network reconnaissance and constrained its communication scope within segmented environments.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely have constrained the malware's ability to access broader network resources and limited its operational scope to isolated workload segments.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have further constrained any potential lateral movement attempts and reduced the attack's ability to discover or access adjacent network resources.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility would likely have detected and constrained the malware's communication patterns with external Telegram bots and proxy infrastructure, limiting command channel reliability.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely have constrained the malware's ability to transmit collected data to external cloud storage services and limited the volume of successful data exfiltration.
While publication of already exfiltrated data would likely still occur, the reduced scope of successfully collected information would limit the campaign's intelligence value and surveillance capabilities.
Impact at a Glance
Affected Business Functions
- Journalism Operations
- Civil Rights Advocacy
- Political Dissent Activities
- Communications Security
Estimated downtime: N/A
Estimated loss: N/A
Comprehensive surveillance data including email communications, chat messages, audio recordings from activated microphones, screenshots revealing contacts and locations, saved passwords, and personal details of Iranian dissidents, journalists, and activists. Some victim information has appeared on pro-Iranian leak sites, increasing physical safety risks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent lateral movement between work and personal devices accessed by targeted individuals
- • Deploy egress security controls with FQDN filtering to block unauthorized data exfiltration to cloud storage services like Vultr and Storj
- • Enable multicloud visibility and anomaly detection to identify suspicious connections to legitimate services being abused for command and control
- • Establish encrypted traffic inspection capabilities to detect malicious use of Telegram API communications and proxy services
- • Implement threat detection and response controls to baseline normal user behavior and alert on covert surveillance tool deployment



