A new warning from cybersecurity agencies in the US, UK and the Netherlands highlights a particularly capable Windows malwarethat authorities say is linked to Iranian state- run cyber operations. The malware can be used to track dissidents, activists and journalists, among other targets.

The FBI has named the threat HEAVYGRAM , while the UK's National Cyber Security Centre (NCSC) is tracking it as CHOSEN BRICK . The joint technical advisory was published on September 15, 2026, and includes new details about the malware's operation, installation, and capabilities .
A spyware with Telegram at the center of its operation
One of the most interesting features of CHOSEN BRICK is its use of Telegram as a command-and-control mechanism. Instead of relying solely on a traditional command server, the malware communicates with a Telegram bot, through which attackers can send commands to the infected system and receive data.
The capabilities that have been documented are extensive. The malware can record the screen, activate the microphone, collect information from emails and data and WhatsApp Telegram available via browser, steal stored credentials, and download additional malicious tools . In some versions, a function to delete data from the computer has even been detected
This means that a successful infection is not limited to stealing a file or password. Access can provide attackers with a much broader picture of the victim's activity.
Dissidents and journalists targeted
The agencies report that CHOSEN BRICK has been used against individuals in the US, UK, Netherlands and other regions of the world, at least since 2025. The NCSC estimates that the broader activity is linked to efforts to suppress individuals considered a threat by the Iranian regime.
See also: Iranian hackers target journalists and dissidents via Telegram
The consequences of such an attack can go far beyond the digital breach. Screen images , messages, contacts , and other data can reveal social relationships, locations, and daily habits .
The NCSC also reports that personal details of previous victims have appeared on pro-Iranian leak websites, which may further increase the risk to their personal safety.
The attack begins with social engineering
CHOSEN BRICK does not necessarily require a sophisticated exploit to reach the computer. The attack can start with a message and a convincing story.
Attackers pose as people known to the target or as technical support representatives from a communication service. After establishing a relationship of trust, they try to convince the victim to open a file.
The files are designed to match the interests or needs of each target. Disguises have been found that refer to applications such as Pictory, RunwayML, Norton Antivirus, Telegram, KeePass, and Adobe Flash Player, while in other cases the file appears to be the result of an MRI scan.
This personalization makes the attack particularly dangerous, as a file that appears relevant to a real conversation is more likely to be opened by the user.

Malware remains active after reboot
Once the malicious file is executed, legitimate-looking content appears on the screen, while CHOSEN BRICK is installed in the background.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The malware uses the Windows Registry Run key to maintain its presence. This way, it can launch again every time the user logs on to the computer, even after a reboot.
At the same time, an attempt has been observed to add exceptions to Microsoft Defenderso that specific files and folders are not checked by the built-in antivirus.
Each infected computer is connected to a different Telegram bot, a practice that allows operators to segregate the activities of each victim.
See also: TELESHIM: Malware exploits Telegram for C2
It is not limited to simple data theft
Available commands allow searching for active processes and system information, taking screenshots, activating the microphone, and collecting data from communication services. The malware can also delete files or download additional malware.
The agencies note that to date, has been observed automatic lateral spread in networks. However, the ability to download additional payloads means that an initial infection can evolve depending on the attacker's commands.
to extract data , while newer versions utilize proxies to better hide communication.
How can signs of infection be detected?
Researchers have published specific Indicators of Compromise (IoCs) that can be exploited by system administrators. These include Registry Run key entries with names like SMQDService and winappx, as well as suspicious folders with unusual paths, such as a directory that includes a space after "Windows."
Clues can also appear in network traffic. Unexpected connections to services such as api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com , and lightningproxies.net are worth investigating when they are not justified by normal system activity.
These indications, however, should not be treated as a complete list, as file names, folders, and other parameters can change.

What users and businesses should do
Cybersecurity services recommend that users not open unexpected files or software sent via messages, even when the sender seems familiar. Programs should be downloaded from official websites or trusted app stores.
Equally important are automatic updates of the operating system and applications, activating and updating antivirus, and paying attention to Windows SmartScreen warnings.
See also: Iranian hackers distribute DCHSpy spyware via fake VPN apps
For businesses, recommendations include phishing-resistant MFA, application allowlisting, device management, endpoint monitoring, and checking logs for known signs of a breach.
In case of suspected infection, simply deleting a suspicious file is not enough. A system audit by the relevant IT department or cybersecurity experts is required, as it must be investigated whether the attacker has gained access to accounts, data, or additional systems.
The new warning shows once again that espionage attacks are not always based on spectacular techniques. A convincing message, a seemingly legitimate file and a communication tool used every day can be the starting point for a serious breach. In the case of CHOSEN BRICK, the technical sophistication of the malware is combined with targeted social engineering, creating a threat that concerns both high-value individuals and any Windows user who might be targeted.
