Full Report
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
Analysis Summary
# Threat Actor: Iran Ministry of Intelligence and Security (MOIS)
## Attribution & Identity
* **Actor identification:** Iran's Ministry of Intelligence and Security (MOIS), the primary intelligence agency of the Iranian government.
* **Aliases:** N/A (The report focuses on the MOIS attribution specifically).
* **Associated Groups:** Linked to pro-Iranian leak sites used for psychological operations and data exposure.
## Activity Summary
* **Campaign Duration:** The wider campaign dates back to the autumn of 2023, with the specific use of the CHOSEN BRICK/HEAVYGRAM malware active since at least 2025.
* **Recent Operations:** A global surveillance campaign detailed in September 2026 by the FBI, NCSC, and AIVD. The operation involves deploying Telegram-controlled malware to spy on individuals deemed threats to the Iranian state, including the use of "leak sites" to harass and endanger victims.
## Tactics, Techniques & Procedures
* **Phishing & Social Engineering:** Posing as trusted contacts or technical support for messaging apps to build rapport.
* **Masquerading:** Using legitimate-looking installers for apps like Pictory (AI video), KeePass, Telegram, RunwayML, Norton Antivirus, and Adobe Flash Player. In some cases, files were disguised as MRI scan results.
* **Persistence:** Adds the malware to the Windows registry "Run" key to ensure execution upon user login.
* **Defense Evasion:** Configures Microsoft Defender exclusions to skip scanning specific malware folders. Use of proxy servers in newer versions to mask Telegram C2 traffic.
* **Command and Control (C2):** Utilizing the Telegram API via dedicated bots for each infected victim to issue commands and exfiltrate data.
* **Capabilities:**
* Audio recording via microphone activation.
* Screen capture (screenshots).
* Credential theft (saved passwords/emails).
* Data theft from browsers (specifically Telegram and WhatsApp data).
* File manipulation (downloading additional tools or deleting/wiping files).
## Targeting
* **Sectors:** Journalism, Human Rights/Activism, Media.
* **Geography:** United Kingdom, United States, Netherlands, and globally.
* **Victims:** Iranian dissidents, journalists opposing the Iranian government, activists, and members of groups with views clashing with the Iranian state. The FBI warns that any individual of interest to the Iranian government is a potential target.
## Tools & Infrastructure
* **Malware Families:**
* **HEAVYGRAM** (FBI designation)
* **CHOSEN BRICK** (NCSC designation)
* **Infrastructure:**
* **C2:** Telegram messaging app (via bots).
* **Exfiltration Points:** Vultr (vultr[.]com), Storj (storj[.]io).
* **Leak Sites:** Pro-Iranian domains (previously seized by the U.S. DOJ) used for doxing and psychological operations.
## Implications
This actor poses a high risk to the physical and digital safety of dissidents and journalists. Beyond standard espionage, the MOIS uses stolen data to fuel psychological operations and facilitate physical threats, including plotting kidnappings or assassinations abroad. The use of common cloud services and Telegram for C2 allows the actor to blend in with legitimate network traffic, making detection difficult for standard home users.
## Mitigations
* **Application Whitelisting:** Restrict the execution of unsigned or unapproved installers, especially those posing as common utilities.
* **Registry Monitoring:** Monitor Windows "Run" keys for unauthorized additions.
* **Antivirus Management:** Audit Microsoft Defender exclusion lists to ensure malware has not added itself to the skip list.
* **Network Auditing:** Monitor for unusual or high-volume traffic to Telegram API endpoints and cloud storage providers like Vultr or Storj, particularly from non-standard processes.
* **Personal Device Security:** Organizations should encourage employees in sensitive roles to maintain the same security rigor on personal devices as they do on work computers, as the actor pivots to personal hardware to bypass corporate defenses.