Overview
- A joint advisory published on September 15 names the spyware family as CHOSEN BRICK (UK) and HEAVYGRAM (US) and attributes the campaign to Iran’s Ministry of Intelligence and Security.
- The malware runs on Windows, connects each infected PC to a unique Telegram bot for control, and can steal emails, browser chats, screenshots and microphone audio.
- Operators use tailored social‑engineering on messaging apps to impersonate trusted contacts or tech support and trick targets into opening disguised files such as fake MRI results.
- Some victims’ personal details have been posted on pro‑Iran leak sites and US authorities seized several such sites in March after previous public warnings about related leaks.
- The advisory publishes technical indicators and step‑by‑step guidance for defenders and at‑risk individuals to check registry Run keys, block listed domains, enable phishing‑resistant MFA and report suspected compromises.