{
  "id": 10124398,
  "title": "Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram",
  "url": "https://urgent.news/2026/09/27/chosen-brick-and-heavygram-iranian-spyware-that-reports-through",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-27T02:40:14.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/chosen-brick-and-heavygram-iranian-spyware-that-reports-through-telegram-4f58"
  },
  "original_language": "en",
  "account": "On 15 September 2026, the UK National Cyber Security Centre, FBI, and Dutch AIVD issued a joint advisory warning of Iranian spyware called Chosen Brick and HEAVYGRAM. These tools have been in use since at least 2025, with the larger operation beginning in autumn 2023. The attackers target victims through WhatsApp and Telegram, posing as a friend or technical support specialist. They deliver a file and request the user run it. The loader operates in two stages, disguised as a legitimate installer. Once installed, the malware sends data to a unique Telegram bot for command and control. Telegram's legitimate status makes it hard to block without incurring costs. The bot channel blends in with normal encrypted traffic. Exfiltration uses Telegram, Vultr object storage, Storj, and Backblaze B2. The spyware can enumerate programs, capture screenshots, record audio, collect data from Telegram and WhatsApp, retrieve browser passwords, and email. One variant deletes files. There is no self-replication, relying on social engineering for propagation. Persistence is maintained through registry Run keys and Defender exclusion folders. Hidden directories with trailing spaces are also used. Indicators include api.telegram.org, vultrobjects.com, storjshare.io, shturl.cc, and commercial proxy providers. Lures in the campaign include well-known software like Pictory, KeePass, Telegram, RunwayML, Norton, Adobe Flash Player, and fake medical results. The FBI provided a FLASH document on the operation, and the U.S. Department of Justice seized four Iranian leak websites in March 2026. Defenders cannot rely solely on blocking Telegram. Network logs may show requests to the Telegram API from unrelated hosts. Registry changes adding Defender exclusions should alert. A hidden directory with a trailing space is a useful file-system indicator. High-risk targets are the main focus. The advisory does not provide victim numbers or specific attribution beyond the named intelligence services. It reflects the agencies' assessment and indicates network indicators for newer builds.",
  "summary": "Chosen Brick and HEAVYGRAM: Iranian Spyware That Reports Through Telegram On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on Windows spyware linked to Iranian intelligence. The two families are tracked as Chosen Brick and HEAVYGRAM. The advisory states that the tooling has been in use since at least 2025, with the wider campaign…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}