News Date: 2026-09-15
A newly detailed cyberespionage campaign shows how familiar messaging and cloud services can be turned into surveillance infrastructure. Security agencies in the United States, United Kingdom and Netherlands say Windows malware known as HEAVYGRAM or CHOSEN BRICK has been used by Iran's Ministry of Intelligence and Security against dissidents, journalists and activists.
Social Engineering Opens the Door
The operation begins with direct contact. Attackers may impersonate a trusted person or technical support representative before sending a file presented as legitimate software or sensitive information. Reported disguises have included Telegram, KeePass, AI applications, antivirus products and even medical scan results.
Opening the file displays a convincing decoy while malware installs in the background. The implant establishes persistence through a Windows registry startup entry and may configure Microsoft Defender exclusions so that selected directories are no longer scanned.
Each compromised computer can communicate with a dedicated Telegram bot. This design allows operators to issue commands and keep activity associated with individual victims separated. The malware can capture screenshots, activate the microphone, collect saved passwords, copy browser-accessible Telegram and WhatsApp information, download additional payloads and delete files. Some versions also support destructive wiping.
Stolen information can be transferred through Telegram and commercial cloud storage services, while newer variants reportedly use proxy infrastructure to obscure communications. This blending of malicious traffic with legitimate platforms can make simple domain blocking impractical.
Protection Requires More Than Indicators
- Block unapproved applications and executable files delivered through messaging services.
- Keep Windows, browsers and security tools fully updated.
- Prevent ordinary users from creating antivirus exclusions.
- Monitor registry startup locations and unusual microphone access.
- Investigate unexpected connections to Telegram APIs, proxy networks and cloud storage providers.
- Provide enhanced protection for journalists, researchers and other high-risk personnel.
In my view, this campaign is especially concerning because the consequences extend beyond conventional data theft. Compromised messages, contacts, screenshots and location clues can expose a victim's professional network and physical routine, potentially creating personal safety risks.
Organizations supporting politically exposed users should assume attackers will switch between corporate and personal devices. Managed endpoints remain important, but secure communication procedures, application control and rapid access to trusted incident response assistance are equally necessary. When cyberespionage is connected to real-world intimidation, endpoint security becomes part of protecting people, not merely protecting information.
