Executive Summary

Since autumn 2023, Iran's Ministry of Intelligence and Security (MOIS) has deployed sophisticated malware called HEAVYGRAM (FBI designation) or CHOSEN BRICK (UK NCSC designation) to conduct extensive cyber espionage operations targeting Iranian dissidents, journalists, and activists worldwide. The Windows-based malware uses Telegram messaging app for command and control, enabling attackers to steal emails, capture screenshots, record audio through microphones, and exfiltrate sensitive communications. Victims are initially compromised through social engineering tactics where attackers impersonate trusted contacts or technical support, delivering malicious files disguised as legitimate applications like Adobe Flash, Norton Antivirus, or even medical scan results.

This campaign represents a significant escalation in state-sponsored surveillance capabilities, demonstrating how authoritarian regimes are weaponizing popular communication platforms for transnational repression. The targeting extends beyond digital espionage, with stolen personal information being published on Iranian leak sites to endanger victims' physical safety, highlighting the intersection of cyber operations with traditional intelligence gathering and intimidation tactics.

Why This Matters Now

Nation-state actors are increasingly leveraging legitimate communication platforms like Telegram for covert operations, making detection more challenging while expanding surveillance capabilities against diaspora communities and dissidents globally.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers impersonate trusted contacts or tech support to deliver malicious files disguised as legitimate software, which then install malware that communicates through dedicated Telegram bots for data theft and surveillance.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this Iranian espionage campaign by limiting malware communication paths and reducing blast radius through network segmentation and controlled egress enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust fabric would likely have limited the initial malware's ability to establish broader network reconnaissance and constrained its communication scope within segmented environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely have constrained the malware's ability to access broader network resources and limited its operational scope to isolated workload segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have further constrained any potential lateral movement attempts and reduced the attack's ability to discover or access adjacent network resources.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility would likely have detected and constrained the malware's communication patterns with external Telegram bots and proxy infrastructure, limiting command channel reliability.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely have constrained the malware's ability to transmit collected data to external cloud storage services and limited the volume of successful data exfiltration.

Impact (Mitigations)

While publication of already exfiltrated data would likely still occur, the reduced scope of successfully collected information would limit the campaign's intelligence value and surveillance capabilities.

Impact at a Glance

Affected Business Functions

  • Journalism Operations
  • Civil Rights Advocacy
  • Political Dissent Activities
  • Communications Security
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Comprehensive surveillance data including email communications, chat messages, audio recordings from activated microphones, screenshots revealing contacts and locations, saved passwords, and personal details of Iranian dissidents, journalists, and activists. Some victim information has appeared on pro-Iranian leak sites, increasing physical safety risks.

Recommended Actions

  • Implement Zero Trust segmentation to prevent lateral movement between work and personal devices accessed by targeted individuals
  • Deploy egress security controls with FQDN filtering to block unauthorized data exfiltration to cloud storage services like Vultr and Storj
  • Enable multicloud visibility and anomaly detection to identify suspicious connections to legitimate services being abused for command and control
  • Establish encrypted traffic inspection capabilities to detect malicious use of Telegram API communications and proxy services
  • Implement threat detection and response controls to baseline normal user behavior and alert on covert surveillance tool deployment

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image