Cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have unveiled a highly coordinated, state-sponsored cyber espionage operation linked to Iran’s Ministry of Intelligence and Security (MOIS). The campaign utilizes advanced Windows-based malware, identified by the FBI as HEAVYGRAM and by the U.K.’s National Cyber Security Center (NCSC) as CHOSEN BRICK, to conduct surveillance on a global scale. By leveraging the Telegram messaging platform as a command-and-control (C2) infrastructure, the MOIS has successfully compromised the digital privacy of activists, journalists, and dissidents, posing a severe threat to their physical and operational security.
Chronology of the Espionage Campaign
The intelligence community’s investigation suggests that the current wave of activity is part of a persistent strategic effort that began to gain momentum in the autumn of 2023. While early indicators of this malicious infrastructure were documented, the scope and sophistication of the operation escalated significantly by 2025.
In March 2026, the FBI issued an initial urgent alert, formally linking the deployment of Telegram-based C2 malware to the Iranian government. This served as a catalyst for a deeper, multi-national investigation. By September 15, 2026, a joint advisory was released by the FBI, the NCSC, and the Netherlands’ General Intelligence and Security Service (AIVD), providing comprehensive technical analysis and updated indicators of compromise (IOCs). This collaborative effort underscores the growing concern among Western intelligence agencies regarding the transnational reach of Iranian digital operations.
Technical Anatomy of HEAVYGRAM and CHOSEN BRICK
The malware operates through a multi-stage infection process designed to bypass modern security protocols. The attack vector typically begins with social engineering; threat actors pose as trusted contacts, colleagues, or technical support personnel within messaging applications. By establishing a rapport with the target, the attackers encourage the download of a seemingly benign file.
Once the target executes the file, the malware initiates a dual-stage deployment. The first stage presents a convincing, non-malicious interface to mask the installation of the second stage, which establishes a persistent connection to a Telegram bot. This bot serves as the nerve center for the operation, allowing the MOIS to transmit commands and receive exfiltrated data without utilizing traditional, more easily detected command-and-control servers.

The technical capabilities of this malware are extensive:
- Surveillance: The malware can activate microphones for real-time audio recording and capture continuous screenshots of the user’s activity.
- Data Exfiltration: It possesses the ability to scrape browser-based credentials, including saved passwords and email addresses, as well as extract chat histories from popular messaging services like Telegram and WhatsApp.
- Persistence: To ensure long-term access, the malware modifies Windows registry "Run" keys, guaranteeing that it launches automatically upon system startup.
- Evasion: It employs sophisticated techniques to modify Microsoft Defender’s scanning exclusions, effectively white-listing its own malicious directories to avoid detection by built-in security software.
The Strategic Context of Iranian Cyber Operations
The use of digital tools to suppress dissent is a hallmark of the Iranian intelligence apparatus. The MOIS does not view these cyber campaigns as isolated events but as a core component of its broader effort to monitor and silence critics living abroad. By mapping the daily routines, social networks, and physical locations of targets, Iranian intelligence creates a profile that can be used for intimidation or, in extreme cases, to facilitate kidnapping or assassination plots.
The impact of this surveillance is compounded by the publication of stolen data on pro-Iranian leak sites. In March 2026, the U.S. Department of Justice took the rare step of seizing four domains associated with these activities. These platforms were not merely repositories for stolen information; they were active propaganda tools used to call for violence against journalists and activists. The transition from digital theft to physical endangerment represents a critical escalation in the threat landscape.
Analysis of the Operational Impact
The choice of Telegram as a primary C2 platform highlights a shift in how threat actors utilize legitimate encrypted services to facilitate illicit operations. By blending in with the massive volume of traffic on such platforms, the attackers complicate the work of defenders who must distinguish between standard user behavior and malicious signaling.
Furthermore, the targeting strategy reveals a deliberate focus on the "human element." By attempting to move from work-related devices to personal computers, the attackers bypass the robust security perimeters often found in corporate environments. This "pivot" strategy assumes that an individual’s personal machine will lack the sophisticated endpoint detection and response (EDR) systems typically deployed in professional settings, rendering the target more vulnerable.
Official Responses and Mitigation Efforts
Following the publication of the joint advisory, international security agencies have emphasized the necessity of a "defense-in-depth" approach. For individuals at high risk—particularly those in the journalistic and activist communities—the agencies recommend the following precautions:

- Vigilance Against Social Engineering: Exercise extreme caution when receiving unsolicited files, even from known contacts. Verify the identity of the sender through a secondary communication channel before opening attachments.
- Regular Audits: Periodically inspect system settings, particularly Windows registry "Run" keys and Microsoft Defender exclusion lists, for unauthorized modifications.
- Endpoint Security: Utilize reputable, up-to-date security software and ensure that all operating systems and applications are patched to the latest versions to mitigate known vulnerabilities.
- Network Segmentation: For administrators, isolate sensitive communications and use Virtual Private Networks (VPNs) to obfuscate traffic, making it harder for unauthorized parties to monitor connection metadata.
Telegram has previously stated that it routinely investigates and removes accounts identified as participating in malicious activities. However, the modular nature of the MOIS campaign suggests that the intelligence services can rapidly rotate accounts and infrastructure, making a permanent eradication of the threat challenging.
The Broader Geopolitical Implications
The disclosure of the HEAVYGRAM/CHOSEN BRICK campaign is indicative of a new normal in international relations, where state-sponsored cyber espionage has become a standard tool of governance for some regimes. The cooperation between the U.S., U.K., and the Netherlands signals a unified front aimed at attributing these actions directly to the MOIS.
While the technical details provided in the joint advisory offer a roadmap for defenders to detect and neutralize specific iterations of the malware, the fundamental challenge remains: the ideological motivation driving these attacks is unlikely to dissipate. As the digital and physical security of dissidents becomes increasingly intertwined, the role of intelligence agencies and private sector security firms in protecting vulnerable populations is expected to grow.
This ongoing campaign serves as a sobering reminder that for journalists and activists operating in the digital age, the "digital footprint" is not just a record of their work, but a potential target for state actors willing to exploit every available technological avenue to stifle opposition. As the investigation continues, the cybersecurity community remains on high alert, monitoring for shifts in the malware’s architecture and the emergence of new, even more stealthy techniques.
