NamesCHOSEN BRICK
(NCSC)
HEAVYGRAM (FBI)
Same malware
ActorIranian MOIS
(Ministry of
Intelligence &
Security)
TargetsDissidents, activists
journalists
UK, US, Netherlands
since 2025
DeliveryWhatsApp / Telegram
social engineering
Fake Norton, KeePass
Telegram, Pictory
MRI scans
CapabilitiesContacts, emails
Screenshots, audio
Browser tokens
Cloud exfil
Device wipe module
Telegram C2
What happened
On September 15, 2026, the UK's NCSC, the FBI, and the Netherlands' AIVD jointly published an advisory naming CHOSEN BRICK, a Windows surveillance implant attributed to Iran's Ministry of Intelligence and Security. The FBI tracks the same malware family under the name HEAVYGRAM; the agencies do not formally declare the two names exact aliases, and analysts should use both in reporting. The campaign has targeted dissidents, activists, and journalists in the UK, US, and Netherlands since at least 2025, with the underlying operation dating to autumn 2023 according to the FBI. The attack chain begins with extensive reconnaissance: operators study the target's network and contacts before approaching on WhatsApp or Telegram, impersonating someone the target already knows or a credible organization. They spend days building rapport before sending the payload. Documented lures include files impersonating Norton Antivirus, Adobe Flash Player, KeePass, Telegram, Pictory, RunwayML, and in one case a fake MRI scan showing a disc herniation tailored to a target known to have a back injury. Once a target opens the file, a decoy screen appears while CHOSEN BRICK installs silently. The malware persists via a HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry entry and immediately begins harvesting contacts, email inboxes, social media messages, and browser authentication tokens. It captures screenshots, activates the microphone for audio recording, and routes exfiltration through cloud object storage services including Vultr, Backblaze, and Storj. Each victim is assigned a unique Telegram bot for command-and-control. CHOSEN BRICK also adds exclusions to Microsoft Defender to evade detection. A data-wiping module is documented in the advisory. The NCSC advisory includes an unusually explicit statement: "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally who they perceive as enemies of the regime."
Why it matters
The CHOSEN BRICK advisory is notable for what it connects: the cyber surveillance campaign is not self-contained. Intelligence agencies in three countries are explicitly linking the same MOIS apparatus that deploys the malware to physical threat planning against the same targets. For journalists, activists, and dissidents with any connection to Iran-related reporting or advocacy, this means the digital risk and the physical risk come from the same actor. For security teams and organizations that employ or work with individuals in those categories, the advisory changes the threat model: detecting CHOSEN BRICK installation is not only a cyber incident but potentially an early warning of an escalating threat to the individual. The tradecraft of spending days building rapport before delivery makes this campaign resistant to standard phishing awareness training, which focuses on unsolicited messages rather than extended trusted relationships.
Don't miss
The advisory documents a specific operational technique worth flagging to at-risk individuals and their security contacts: CHOSEN BRICK operators reportedly prefer to approach the target's work device first, then steer the conversation to a personal device specifically to move outside corporate security controls. The transition from a work conversation to "let's continue this on my personal WhatsApp" is not incidental. It is the designed step that moves the delivery outside the perimeter where endpoint detection, email scanning, and DLP controls operate. At-risk individuals should apply the same skepticism to trusted-feeling contacts requesting file transfers on personal messaging apps as they would to unsolicited phishing, particularly when the file is something personal or medical in nature.
Potential actions
- Organizations employing journalists, human rights workers, researchers, or advocates who cover Iran-related topics should brief those individuals on the CHOSEN BRICK advisory and its indicators. The joint FBI/NCSC/AIVD IoC release includes file hashes, registry persistence locations, and network indicators for cloud exfiltration traffic. Review endpoint telemetry for the HKCU Run key persistence entries, Defender exclusion modifications, and outbound connections to Vultr, Backblaze, and Storj from endpoints that do not normally use those services.
- At-risk individuals should treat any inbound file from a WhatsApp or Telegram contact as suspicious if the file was unexpected, arrived after an unusually attentive outreach period, or the sender pivoted the conversation from a professional channel to a personal messaging app before sending it. Do not open files from messaging apps on a primary work or personal device; use an isolated analysis environment or submit the file to a malware sandbox before opening. Report any suspected contact to the organizations in the advisory: UK NCSC's report form, FBI's IC3, or Netherlands' AIVD.
The Sip
Spend days gaining the target's trust. Send a fake MRI scan tailored to their known medical history. Wait for them to open it on their personal phone away from corporate controls. Harvest everything. The same MOIS apparatus has plotted to kill some of the people it surveils this way. This is not a phishing campaign. It is the digital component of a physical repression program. Journalists and dissidents covering Iran need to see this advisory.