US, UK and Dutch Agencies Warn Iran's Chosen Brick Spyware Spies on Dissidents via Telegram
A 15 September 2026 joint advisory from the UK NCSC, US FBI, and Netherlands AIVD says CHOSEN BRICK, also called HEAVYGRAM, has targeted dissidents, journalists, and activists since at least 2025. All observed infections are Windows PCs.

The UK National Cyber Security Centre, with the US FBI and the Netherlands AIVD, published a joint advisory on 15 September 2026 on CHOSEN BRICK malware. The FBI's technical CSA also calls the family HEAVYGRAM and attributes it to Iran's Ministry of Intelligence and Security (MOIS). An allies news note went out the same day.
This is a joint government cyber advisory. It is an intelligence assessment, not a court judgment.
The agencies say the malware has been used against dissidents, journalists, and activists in the UK, the US, the Netherlands, and globally since at least 2025. FBI materials date a wider campaign to autumn 2023. Victim personal details have appeared on pro-Iran leak sites. The agencies link that collection to repression and, in some cases, plots to kidnap or kill abroad.
Delivery is social engineering over WhatsApp and Telegram, posing as known contacts or tech support. Lure files have impersonated Pictory, KeePass, Telegram, RunwayML, Norton Antivirus, Adobe Flash Player, and, in some cases, MRI results. Command and control runs through a Telegram bot unique to each victim. Stolen data has also left through Vultr, Storj, and other cloud or proxy services.
Telegram is the lure and control channel, not the infected operating system. In all observed cases the malware hits Windows PCs only. Operators often try a work machine first, then ask the target to open the installer on a personal device after corporate controls block them.
Capabilities include screenshots, microphone capture, theft of Telegram and WhatsApp browser data, emails and passwords, and downloading more malware. At least one version can wipe the PC. Persistence uses a Run key named SMQDService or winappx. The malware adds Microsoft Defender exclusions, writes extra tools to a spaced path (C:\Windows \SysWOW64, with a space after Windows), and has not been observed spreading sideways on its own, though extra downloads are possible.
Defenders should hunt those Run keys, the spaced SysWOW64 path, and unexpected traffic to Telegram bot APIs plus Vultr, Storj, Backblaze, and the proxy hosts named in the NCSC advisory.
Related lure and spyware tape includes how to prevent phishing attacks, Microsoft passkey lures into Microsoft 365 theft, and HBO Max Reddit ClickFix malware.
At-risk staff should refuse unexpected installers from chat apps, check Run keys for SMQDService or winappx, and circulate the NCSC/FBI advisory to personal-device users as well as corporate IT.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free