CYOPS · Cyber Operations

One spyware family, two government names, and a target list made of people rather than networks

A joint NCSC, FBI and AIVD advisory named CHOSEN BRICK on 15 September. The FBI published the same malware as HEAVYGRAM the same day. The tradecraft is commodity, the delivery is a message from someone you know, and the consequences reported by the agencies are physical.

One malware family, two names, published the same day

On 15 September 2026 the UK National Cyber Security Centre, the US Federal Bureau of Investigation and the Netherlands General Intelligence and Security Service published a joint advisory on a Windows malware family they call CHOSEN BRICK [1][2][3]. The same day, the FBI published a FLASH updating FLASH-20260320-001 describing the same tooling under the name HEAVYGRAM [4][5].

That is worth pausing on before the tradecraft. A detection rule written against one name will not match intelligence keyed to the other. A threat-intelligence platform ingesting both documents will hold two entries unless someone merges them by hand. The naming problem is ordinary in this field, but it is unusual to see it created on the same day by overlapping agencies, and it is a correlation cost carried by every defender downstream.

The attribution belongs to the agencies. The NCSC assesses that “Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime” [1][3]. The FBI states that it “assesses that Iranian cyber actors are using HEAVYGRAM malware to conduct malicious cyber activity to target Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS)” [4]. R3KONX asserts nothing beyond reporting those assessments.

The target is a person, and the device is whichever one works

The targeting is dissidents, activists and journalists, worldwide, including in the UK, the US and the Netherlands, and the activity runs since at least 2025 [1][3][6]. Delivery is social rather than technical: operators impersonate known contacts or platform support staff on WhatsApp and Telegram, build rapport over time, then send a file [1][6][7]. Lures have been disguised as legitimate software including Norton Antivirus, Adobe, KeePass, Pictory and RunwayML, and as documents such as fake MRI scan results [2][6][8].

The operationally important detail is in the targeting sequence. Reporting on the advisory records that attackers prioritise work devices and pivot to personal devices when workplace security blocks access, which exploits the fact that organisations have limited control over employees’ personal phones and computers [7]. For any organisation that employs journalists, researchers or staff from affected diaspora communities, that describes a risk the organisation carries without owning the endpoint on which it lands.

The consequence is not confined to data. The NCSC records that “personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites” [2], and states that “in some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime” [9]. Paul Chichester, NCSC Director of Operations, said the campaign “reveal[s] how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime” [10]. A compromise here is a physical-safety problem for the person, not an information-security problem for a company.

The tradecraft is cheap, legitimate-looking and well documented

Nothing in the technical description is novel, and that is the point. Persistence is a registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run using service-like names, so the malware survives a reboot [2][5][8]. It adds Windows Defender exclusions so its files and directories are not scanned [5]. It is Windows-only [1][6].

Command and control runs through the Telegram API using bot tokens and chat IDs, with a separate bot per infected device; newer variants add HTTPS and SOCKS5 proxies [4][6][8]. Exfiltration uses the Telegram API and commercial object storage, specifically Vultr buckets at ams1.vultrobjects.com and StorjShare [4][8]. Collection covers screen capture, microphone recording, keylogging, process enumeration, browser data from Chrome, Firefox and Edge, Telegram and WhatsApp message caches, and Gmail credential theft via OAuth2 interception [4][6]. The malware can also delete files and wipe a device entirely [6][10].

The FBI FLASH names executables including winappx.exe, smqdservice.exe, RuntimeSSH.exe and MsCache.exe, and staging directories under %ALLUSERSPROFILE%\ZlibDate\, C:\ProgramData\SMQDServicePackages\ and C:\ProgramData\Drivers\MicDriver\ [4]. SafeBreach maps the behaviour to MITRE ATT&CK techniques including T1566.003 for the messaging-app delivery, T1547.001 for the Run key, T1685 for the Defender exclusion abuse, T1113 for screen capture and T1123 for audio capture [5].

Every one of those components is commodity. The expensive part of this operation is the human research that makes a message from a supposed acquaintance plausible enough to open, and that part does not appear in any indicator list.

What to do

  • Alert on Windows Defender exclusion changes. It is the single highest-value detection here, it is cheap to implement, and legitimate exclusion changes should be rare and attributable [5].
  • Hunt registry Run values pointing at paths under C:\ProgramData\, and review the named staging directories and executables from the FBI FLASH [4][5].
  • Treat outbound traffic to api.telegram.org and to commercial object storage such as vultrobjects.com or StorjShare as reportable where no business justification exists [4][5][8].
  • Brief at-risk staff on the specific pattern rather than on phishing in general: a known contact, rapport built over days, then a file sent through WhatsApp or Telegram [1][6][7].
  • Decide the personal-device question deliberately. If staff are targeted because of their work, the pivot to personal devices is foreseeable and needs a policy answer rather than an assumption [7].
  • Point individuals at the support that exists. The NCSC offers free cyber defence services to high-risk individuals, and its guidance on transnational repression is written for exactly this population [1][3].
  • Record both names, CHOSEN BRICK and HEAVYGRAM, in your intelligence platform as one entity, before a rule written against one of them silently fails to fire [4][5].

Domain close

Most of what a security team reads describes operations against organisations, where the harm is measured in records, downtime or money. This one is aimed at individuals, and the agencies publishing it have said in plain language what the collected material has been used for. It also sits almost entirely outside the enterprise perimeter: a messaging app, a personal laptop, a Telegram bot and a commercial storage bucket. There is no appliance to patch and no exploited vulnerability to inventory. What exists instead is a small set of cheap, specific detections, a population of people who can be told precisely what the approach looks like, and a decision about whether an organisation accepts responsibility for the devices its at-risk staff actually use.

Sources

Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.

  1. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists UK National Cyber Security Centre · 2026-09-15
  2. Iranian cyber targeting of dissidents, activists and journalists UK National Cyber Security Centre · 2026-09-15
  3. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists (advisory PDF) UK National Cyber Security Centre · 2026-09-15
  4. Update on Government of Iran Cyber Actors' Deployment of Telegram C2 to Push Malware to Identified Targets (FLASH, update to FLASH-20260320-001) US Federal Bureau of Investigation via Internet Crime Complaint Center · 2026-09-15
  5. CHOSEN BRICK Spyware: SafeBreach Coverage for the NCSC-FBI-AIVD Joint Advisory SafeBreach · 2026-09-15
  6. Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists Help Net Security · 2026-09-16
  7. Chosen Brick, Iran's Surveillance Malware Security Affairs · 2026-09-17
  8. Iran's CHOSEN BRICK Spyware Exposed by NCSC, FBI, AIVD TechNadu · 2026-09-15
  9. UK and allies expose Iranian spyware campaign Computing · 2026-09-16
  10. CHOSEN BRICK: What We Know about Iranian Spyware Cyber Magazine · 2026-09-17

Researched and written by the R3KONX analysis desk from the cited primary material: the joint NCSC, FBI and AIVD advisory and its supporting publication, and the FBI's separately published FLASH on the same malware, with vendor and trade reporting used to corroborate. Methodological caveats: all attribution in this article is the issuing agencies' own assessment and is reported as such, not as an R3KONX finding; the two documents describe the same malware under two different names, and the equivalence is stated by the publishers rather than derived here; no victim count has been published and none is asserted; indicators are reproduced from government advisories as defensive material. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.