Iranian MOIS Deployment of HEAVYGRAM and CHOSEN BRICK
Score: 9/10

Iranian MOIS Deployment of HEAVYGRAM and CHOSEN BRICK

The Iranian Ministry of Intelligence and Security (MOIS) uses HEAVYGRAM (aka CHOSEN BRICK) malware to target dissidents and journalists via social engineering and Telegram-based command-and-control.

Executive Summary

The FBI, NCSC, and AIVD have identified a coordinated espionage campaign attributed to the Iranian Ministry of Intelligence and Security (MOIS) active since late 2023. The campaign, titled CHOSEN BRICK, utilizes custom Windows malware families—HEAVYGRAM, RuntimeSSH, and MsCache—to target Iranian dissidents, activists, and journalists. The primary goal is intelligence collection, reputational harm, and the potential facilitation of physical harm through data leaks.

The attack chain typically begins with social engineering on platforms like Telegram, WhatsApp, and Instagram, where actors offer IT services to deliver malicious installers masquerading as legitimate tools such as Pictory, KeePass, or Telegram. Once installed, the malware uses Telegram bots for Command and Control (C2) and exfiltrates sensitive data including browser credentials, messaging history, and real-time audio/screen recordings. Persistence is maintained through registry modifications and antivirus exclusions.

This activity represents a high threat to individuals and organizations perceived as opposition to the Iranian government. The ability of the malware to record live audio and steal session tokens for major communication platforms significantly increases the risk of physical surveillance and kidnapping plots, as noted by the joint agencies.

Key Details

Threat Name

HEAVYGRAM Malware

Affects

—

Adversary

Ministry of Intelligence and Security Other Adversaries and Aliases: ShinyHunters

Malware/Tools

HEAVYGRAM, winappx.exe, MsCache.exe, RuntimeSSH.exe, smqdservice.exe, KeePass.exe, MicDriver, MDll.dll, CHOSEN BRICK, Rapuncel

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance8
Clarity & Structure8
Technical Depth9

Sources