Iranian MOIS Deployment of HEAVYGRAM and CHOSEN BRICK
Score: 9/10

Iranian MOIS Deployment of HEAVYGRAM and CHOSEN BRICK

The Iranian Ministry of Intelligence and Security (MOIS) uses HEAVYGRAM/CHOSEN BRICK malware to target dissidents and journalists via Telegram-based command and control.

Executive Summary

The FBI, NCSC, and AIVD have identified a sophisticated espionage campaign attributed to the Iranian Ministry of Intelligence and Security (MOIS) targeting Iranian dissidents, journalists, and opposition groups worldwide. Active since at least Fall 2023, the campaign—dubbed CHOSEN BRICK or HEAVYGRAM—leverages social engineering on platforms like Telegram, WhatsApp, and Instagram to deliver modular Windows-based malware masquerading as legitimate installers for tools like AnyDesk, Pictory, and KeePass.

The attack chain involves multi-stage Python-based implants that utilize Telegram bots for command-and-control (C2) and Vultr S3 buckets for data exfiltration. Technical analysis reveals high-impact surveillance capabilities, including keystroke logging, screen and audio recording (specifically targeting Zoom calls), and the automated extraction of credentials and session data from browsers (Chrome, Edge, Firefox) and communication platforms (WhatsApp, Telegram, Outlook).

This activity poses a significant threat to the physical and digital safety of targeted individuals, as stolen data is often published on pro-Iranian leak sites to facilitate reputational harm or physical threats. Organizations and individuals at risk should prioritize monitoring for the specific persistence mechanisms and Telegram-based C2 traffic identified in this intelligence.

Key Details

Threat Name

HEAVYGRAM Malware

Affects

—

Adversary

Ministry of Intelligence and Security

Malware/Tools

HEAVYGRAM, winappx.exe, MsCache.exe, RuntimeSSH.exe, smqdservice.exe, KeePass.exe, MicDriver, MDll.dll

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources