Executive Summary
The FBI, NCSC, and AIVD have identified a sophisticated espionage campaign attributed to the Iranian Ministry of Intelligence and Security (MOIS) targeting Iranian dissidents, journalists, and opposition groups worldwide. Active since at least Fall 2023, the campaign—dubbed CHOSEN BRICK or HEAVYGRAM—leverages social engineering on platforms like Telegram, WhatsApp, and Instagram to deliver modular Windows-based malware masquerading as legitimate installers for tools like AnyDesk, Pictory, and KeePass.
The attack chain involves multi-stage Python-based implants that utilize Telegram bots for command-and-control (C2) and Vultr S3 buckets for data exfiltration. Technical analysis reveals high-impact surveillance capabilities, including keystroke logging, screen and audio recording (specifically targeting Zoom calls), and the automated extraction of credentials and session data from browsers (Chrome, Edge, Firefox) and communication platforms (WhatsApp, Telegram, Outlook).
This activity poses a significant threat to the physical and digital safety of targeted individuals, as stolen data is often published on pro-Iranian leak sites to facilitate reputational harm or physical threats. Organizations and individuals at risk should prioritize monitoring for the specific persistence mechanisms and Telegram-based C2 traffic identified in this intelligence.
Key Details
Threat Name
HEAVYGRAM Malware
Affects
—
Adversary
Ministry of Intelligence and Security
MITRE Techniques
Malware/Tools
HEAVYGRAM, winappx.exe, MsCache.exe, RuntimeSSH.exe, smqdservice.exe, KeePass.exe, MicDriver, MDll.dll
