Iran MOIS: HEAVYGRAM / CHOSEN BRICK Telegram-C2 malware targets dissidents (FBI / NCSC / AIVD)
Joint advisory published 15 September 2026 by the UK NCSC, US FBI, and Netherlands AIVD details Windows malware the FBI calls HEAVYGRAM and NCSC calls CHOSEN BRICK, attributed to Iran's Ministry of Intelligence and Security (MOIS). Operators build rapport on messaging apps, then deliver trojanised installers (lures include Pictory, KeePass, Telegram, RunwayML, Norton, Adobe Flash, and MRI-scan themed files), often starting on work devices before pivoting to personal ones. Malware is controlled via Telegram and can copy emails/chat messages, take screenshots, and activate the microphone; NCSC dates use from at least 2025 against people in the UK, US, Netherlands and elsewhere (FBI dates the wider campaign to autumn 2023). Victim details have appeared on pro-Iranian leak sites, raising personal-safety risk. FBI IC3 CSAs (260915 / 260915-2) expand a March 2026 alert with further TTPs and IoCs. Primary: NCSC advisory + FBI/IC3; wire: The Hacker News 15 Sep.
- Product
- HEAVYGRAM / CHOSEN BRICK (Windows; Telegram C2)
- Exploited in Australia?
- unknown
- Patch to
- Individuals at risk: verify unexpected app installs; enable MFA; report targeting to national cyber centres; defenders: hunt Telegram C2 beacons and IoCs in NCSC/FBI packages
Primary: NCSC — Iranian cyber targeting / CHOSEN BRICK advisory (15 Sep 2026) · Vendor: FBI IC3 CSA 260915 — HEAVYGRAM / Iran MOIS Telegram C2 (PDF) · The Hacker News — Iranian Telegram-controlled malware (15 Sep 2026)
