International Cybersecurity Coalition Exposes Iranian State-Sponsored Spyware Campaign Targeting Dissidents and Journalists Worldwide

In a coordinated international disclosure, cybersecurity and intelligence agencies from the United States, the United Kingdom, and the Netherlands have released comprehensive technical advisories detailing a sophisticated Windows malware campaign orchestrated by Iranian state-sponsored actors. The operation, which has been active since at least the autumn of 2023, utilizes specialized surveillance tools to target Iranian dissidents, independent journalists, political activists, and civil society members across the globe.
According to the joint technical assessment, the primary objective of the campaign is transnational repression. The malware acts as a remote access trojan (RAT) that allows operators to harvest sensitive communications, monitor daily routines, and extract confidential personal data. The findings highlight an increasing reliance by state-sponsored intelligence apparatuses on commercial messaging platforms and cloud infrastructure to command and control espionage operations, blurring the lines between traditional cyber warfare and targeted surveillance.
The Anatomy of HEAVYGRAM and CHOSEN BRICK
The surveillance toolkit at the center of the advisory has been cataloged under different designations by participating nations. The United States Federal Bureau of Investigation (FBI) refers to the primary malware variant as HEAVYGRAM, while the United Kingdom’s National Cyber Security Center (NCSC) has designated it CHOSEN BRICK. The AIVD, the intelligence and security service of the Netherlands, corroborated these findings, noting that the infrastructure has been deployed extensively against individuals residing within their respective borders and internationally.
Attribution for the campaign has been directed firmly at Iran’s Ministry of Intelligence and Security (MOIS). The MOIS, historically known for conducting foreign intelligence operations, physical surveillance, and operations against domestic opposition groups, appears to have integrated this advanced cyber capability to extend its reach far beyond Iran’s physical borders.
The malware itself is exceptionally versatile and relies on Windows operating systems for execution. Once a target system is compromised, the malware establishes communication loops through the Telegram messaging application. By leveraging Telegram bots and proxy servers, the threat actors maintain persistent, encrypted channels to exfiltrate data while masking the physical location of the command-and-control servers.
A Chronology of the Threat Campaign
The public exposure of this espionage network is the culmination of a multi-year intelligence-gathering effort by Western cybersecurity agencies. The timeline of the campaign reveals a steady evolution in sophistication and scale:
- Autumn 2023: Initial indicators of the wider espionage campaign are detected by intelligence partners, marking the presumed beginning of the operational deployment phase for the targeted surveillance tools.
- 2025: Operational expansion becomes evident, with documented intrusions targeting high-profile dissidents, opposition journalists, and human rights defenders residing in the U.S., U.K., and the Netherlands.
- March 2026: The FBI issues its initial public security alert regarding government-sponsored Iranian cyber actors utilizing Telegram-based command-and-control frameworks to push malware to identified targets. Concurrently, the U.S. Department of Justice executes disruptive actions against four pro-Iranian leak sites used to host stolen data and amplify psychological operations.
- September 15, 2026: A formal tripartite advisory is published jointly by the NCSC, the FBI, and the AIVD. This release is accompanied by updated technical analyses, specific indicators of compromise (IoCs), and cryptographic file hashes designed to assist enterprise and personal defenders in identifying the threat.
How the Infiltration Strategy Operates

The attack vector typically begins with targeted social engineering. Rather than deploying automated, widespread phishing campaigns, the operatives engage in meticulous preparation. Attackers frequently pose as trusted acquaintances, colleagues, or technical support representatives for popular communication applications. By establishing a veneer of legitimacy and trust, they induce the target to download and execute a malicious payload.
The initial delivery often prioritizes work environments, as professional systems may lack the aggressive personal monitoring tools used by individuals, or because professional circles offer broader access to contacts. If initial corporate vectors fail, operators pivot to personal devices, which are often less protected by institutional security architectures.
The malware is routinely disguised as legitimate software installers or productivity tools. Documented disguises include popular AI video generation platforms such as Pictory and RunwayML, password managers like KeePass, installations of Telegram itself, Norton Antivirus, Adobe Flash Player, and, in some highly targeted instances, files deceptively formatted to resemble sensitive medical documents such as MRI scan results.
Upon execution, the application displays a convincing decoy interface to the user—functioning superficially as the expected program—while simultaneously deploying the multi-stage malware payload in the background. The first stage executes the visual shell, while the second stage establishes persistent communication with a designated Telegram bot.
To survive system reboots, the malware inserts malicious registry keys into the Windows "Run" registry hive, ensuring automatic execution upon user login. Furthermore, advanced variants actively modify configurations for Microsoft Defender and other local security products, instructing the built-in antivirus to bypass specific directories and avoid scanning the malicious files.
Capabilities and Data Exfiltration Methods
Once active on a compromised machine, the malware grants its operators comprehensive surveillance capabilities. The technical advisories indicate that HEAVYGRAM and CHOSEN BRICK can perform a vast array of intrusive actions:
- Enumerating running processes and installed applications.
- Capturing high-resolution screenshots at regular intervals or upon specific triggers.
- Activating local microphones to covertly record ambient audio.
- Extracting session tokens, chat histories, and contact lists from browsers for applications like Telegram and WhatsApp.
- Harvesting saved browser credentials, autofill data, and email client databases.
- Downloading and executing secondary payloads, tools, or diagnostic scripts.
- Executing destructive commands, including file wiping functions seen in select iterations.
Data exfiltration is primarily managed through the established Telegram bot infrastructure, though attackers have also incorporated cloud storage services such as Vultr and Storj to handle larger data transfers. Newer iterations of the toolchain introduce proxy servers to obscure the traffic paths, making network-level attribution and blocking significantly more complex for corporate and residential defenders.
Broader Implications for Transnational Repression
The integration of cyber espionage with physical security threats underscores a dangerous evolution in modern state-sponsored intelligence operations. Security agencies emphasize that the compromise goes far beyond data privacy violations. The harvesting of locations, daily routines, personal contacts, and confidential communications provides hostile intelligence services with the necessary intelligence to facilitate physical harassment, intimidation, or targeted kinetic operations abroad.

This digital-physical nexus was underscored earlier in the year when U.S. authorities seized pro-Iranian leak sites utilized to publish stolen material. Beyond simple data publication, those platforms had been leveraged to coordinate psychological operations and direct threats against individuals who vocalize opposition to the Iranian government. Consequently, intelligence partners view the disruption of this malware infrastructure not merely as an IT security measure, but as a critical intervention to protect human life.
Official Responses and Industry Reaction
Following the initial disclosures by the FBI, representatives from Telegram addressed the platform’s misuse by state-backed actors. Company spokespersons affirmed that platform moderators routinely monitor and purge accounts identified as engaging in malicious activities, including malware deployment and coordinated harassment campaigns. However, security analysts note that the decentralized and rapidly regenerating nature of bot creation presents an ongoing challenge for platform moderation teams.
The release of the September 2026 advisory represents a strategic shift toward proactive transparency by Western intelligence bodies. By sharing granular technical indicators, memory signatures, and network traffic patterns, governments aim to empower independent journalists, human rights organizations, and political activists—demographics that traditionally lack dedicated enterprise security teams—to audit their systems and mitigate potential compromises.
Mitigation and Defense Recommendations
To counter the threat posed by HEAVYGRAM and CHOSEN BRICK, the issuing cybersecurity authorities have outlined comprehensive defensive frameworks tailored for both individual users and enterprise network administrators.
For individual users, particularly those identified as high-risk due to their public profiles, political affiliations, or journalistic activities, recommendations include:
- Exercising extreme caution when receiving software installers, documents, or updates via messaging platforms, even if the sender appears familiar.
- Verifying software downloads exclusively through official vendor websites rather than third-party repositories or direct links provided in chats.
- Regularly auditing startup programs, scheduled tasks, and the Windows registry "Run" keys for unauthorized or unfamiliar persistence mechanisms.
- Enabling robust multi-factor authentication (MFA) across all personal and professional accounts, prioritizing hardware-based security keys where feasible.
For network and system administrators:
- Implementing strict application control policies to prevent the execution of unauthorized binaries and scripts.
- Monitoring endpoint telemetry for anomalous outbound traffic connecting to messaging application APIs or unauthorized cloud storage providers.
- Conducting regular threat-hunting exercises utilizing the cryptographic hashes and indicators of compromise detailed in the official FBI and NCSC advisories.
- Ensuring that endpoint detection and response (EDR) solutions are configured to alert on attempts to modify local antivirus exclusion lists or security policies.
As geopolitical tensions continue to manifest in the digital domain, international cooperation among cybersecurity agencies remains a cornerstone in countering state-sponsored espionage and protecting vulnerable populations from digital and physical harm.






