Executive Summary
The FBI, NCSC, and AIVD have identified a coordinated espionage campaign attributed to the Iranian Ministry of Intelligence and Security (MOIS) active since late 2023. The campaign, titled CHOSEN BRICK, utilizes custom Windows malware families—HEAVYGRAM, RuntimeSSH, and MsCache—to target Iranian dissidents, activists, and journalists. The primary goal is intelligence collection, reputational harm, and the potential facilitation of physical harm through data leaks.
The attack chain typically begins with social engineering on platforms like Telegram, WhatsApp, and Instagram, where actors offer IT services to deliver malicious installers masquerading as legitimate tools such as Pictory, KeePass, or Telegram. Once installed, the malware uses Telegram bots for Command and Control (C2) and exfiltrates sensitive data including browser credentials, messaging history, and real-time audio/screen recordings. Persistence is maintained through registry modifications and antivirus exclusions.
This activity represents a high threat to individuals and organizations perceived as opposition to the Iranian government. The ability of the malware to record live audio and steal session tokens for major communication platforms significantly increases the risk of physical surveillance and kidnapping plots, as noted by the joint agencies.
Key Details
Threat Name
HEAVYGRAM Malware
Affects
—
Adversary
Ministry of Intelligence and Security Other Adversaries and Aliases: ShinyHunters
MITRE Techniques
Malware/Tools
HEAVYGRAM, winappx.exe, MsCache.exe, RuntimeSSH.exe, smqdservice.exe, KeePass.exe, MicDriver, MDll.dll, CHOSEN BRICK, Rapuncel
