Advanced Persistent Threats

Chosen Brick: The MOIS-Linked Espionage Chain From Messaging Apps to Computer Surveillance

A new warning from the UK, the US, and the Netherlands details, one that begins by gaining a target’s trust and can end with stolen communications, audio surveillance, and the publication of personal information for further harassment.

Raaznet Research Team
Raaznet Research TeamOSINT investigations, digital forensics, network security, and data analysis documenting the infrastructures, tools, and actors behind surveillance and digital threats.
September 18, 2026
21 min read
Chosen Brick: The MOIS-Linked Espionage Chain From Messaging Apps to Computer Surveillance

On September 15, 2026, the FBI and security agencies in the United Kingdom and the Netherlands published new details about a malware family used to spy on dissidents, journalists, activists, and others viewed by the Islamic Republic as threats. The FBI tracks the family as HEAVYGRAM and attributes its use to cyber actors operating on behalf of Iran’s Ministry of Intelligence and Security, or MOIS. The UK National Cyber Security Centre tracks the same malware family as CHOSEN BRICK, according to a joint advisory.

The FBI report is based on the analysis of seven malware samples and traces use of the toolset back to at least the fall of 2023. The joint advisory from the NCSC, FBI, and the Netherlands’ General Intelligence and Security Service says CHOSEN BRICK samples have been used since at least 2025 against specific targets in multiple countries, including the United Kingdom, the United States, and the Netherlands.

The different names reflect different tracking conventions rather than two separate operations. Technical overlaps make the connection clear. Components such as winappx.exe and SMQDService, analyzed by the FBI as part of HEAVYGRAM, also appear in the joint advisory as components associated with CHOSEN BRICK. Installation paths, Windows persistence mechanisms, manipulation of Microsoft Defender, and the use of Telegram for command-and-control also overlap across both reports. Security researchers comparing the two advisories have likewise described HEAVYGRAM and CHOSEN BRICK as separate names for the same malware family.

From Stolen Research Papers to Targeted Espionage

The networks behind these operations predate HEAVYGRAM by years. At a time when the buying and selling of academic papers and dissertations had become a visible business around Tehran’s Enghelab Square, the Mabna Institute built a much larger system for obtaining academic material. According to a US Department of Justice case, the network targeted more than 100,000 university professors beginning in 2013 and compromised roughly 8,000 accounts at universities in the United States and other countries, stealing journal articles, dissertations, books, and other academic material. Some of the stolen material was later sold to customers in Iran through the Megapaper and Gigapaper websites.

The network’s activities were not limited to academic theft. A superseding US indictment issued in 2026 also connected members of the network to the 2017 breach of HBO, in which unreleased episodes, scripts, Game of Thrones plot summaries, and other internal material were stolen before attackers demanded millions of dollars to withhold the data. The case sits within a broader history of cyber operations attributed to entities linked to the Islamic Republic. In a separate case, US prosecutors charged seven hackers working for companies contracted by the Islamic Revolutionary Guard Corps with large-scale attacks against 46 organizations, mostly in the US financial sector, as well as unauthorized access to the control system of a dam in New York.

One of the individuals named in the new indictment is Amir Barati, a hacker arrested in Kotor, Montenegro, on June 25, 2026, at the request of US authorities. RazNet examined the similarities between his case and the Mabna Institute network before the superseding indictment was released. Two months later, the US Department of Justice formally placed Barati within the Mabna network and accused him of helping compile target lists, conduct network reconnaissance, prepare phishing messages, track operations, and exchange information from compromised accounts. The August 2026 indictment names 17 Iranian nationals and describes a network of hackers-for-hire and cyber contractors working for government entities and other clients.

An investigation by Shahid Alavi for Iran International offers another view of how parts of that network continued operating after the original Mabna members were exposed. According to sources cited in the investigation, some members continued their work from October 2018 under a project known as Sombol, operating under the direction of the Ministry of Intelligence. The report links three officials involved in MOIS cyber operations — Avazali Nourian, Mojtaba Javanbakht, and Mohammad-Amin Fasihi Dastjerdi — to Sombol and its operators, and says operational personnel received servers, target lists, and intrusion assignments.

The model meant that operators did not necessarily need to be formal MOIS employees. Contractors, private companies, and intelligence intermediaries could carry out operations for security agencies without every participant appearing directly inside the ministry’s administrative structure.

This history raises an important question about HEAVYGRAM and CHOSEN BRICK. The new US indictment places some of the same individuals inside the Mabna network and later operations that Iran International’s sources identify as part of Sombol and the Ministry of Intelligence’s contractor ecosystem. At the same time, the techniques associated with this cluster — detailed target selection, target lists, spearphishing, social engineering, account theft, and malware-enabled persistent access — closely resemble the operational model documented for HEAVYGRAM and CHOSEN BRICK.

Based on these overlaps, the final assesment is that HEAVYGRAM/CHOSEN BRICK is likely part of the technical toolkit used by this broader operational ecosystem or networks that evolved from it.

The Attack Begins With the Target, Not the Malware

HEAVYGRAM has been documented as part of targeted operations rather than mass malware distribution. The attacker first selects a specific individual and gathers enough information to construct a believable identity or pretext. The joint advisory says operators may impersonate someone already known to the target or pose as technical support for a messaging service.

Initial contact commonly takes place through messaging platforms such as Telegram and WhatsApp. The FBI also documented Instagram in the cases it examined. One recurring pretext is technical assistance: the attacker first establishes trust, then attempts to persuade the target to install software or open a file.

In some cases, targets have been asked to install the legitimate remote-access application AnyDesk and provide the information required to establish a remote connection. In others, the attacker sends a malicious application that starts the infection chain when executed. AnyDesk itself is not malware in this scenario; its legitimate remote-access functionality is being abused after the victim has been socially engineered into providing access.

The HEAVYGRAM attack vector shows the progression from target selection and deception through malware deployment, data collection, and the eventual use of stolen information:

1. Target selection: A specific person — such as a dissident, journalist, or activist — is selected and researched.

2. Initial contact: The attacker approaches the target through Telegram, WhatsApp, or another messaging platform using a credible identity.

3. Trust building: A pretext tailored to the target, such as technical assistance or a seemingly legitimate file, is used to establish trust.

4. Execution or remote access: The victim executes a masquerading application or enables remote access through a tool such as AnyDesk.

5. Malware deployment: HEAVYGRAM / CHOSEN BRICK components are executed and installed on the device.

6. Persistence: The malware registers itself to run again after Windows restarts.

7. Data collection: Messages, email, browser data, screenshots, files, and in some cases microphone audio can be collected.

8. Exfiltration: Data is sent through infrastructure including Telegram bots and cloud-storage services.

9. Use of stolen data: The information can be used to map the victim’s contacts, expand targeting, exert pressure, threaten the target, or publish private information.

The operators also distinguish between corporate and personal devices. According to the joint advisory, an approach may begin on a work system, but if deployment fails or endpoint security creates a risk of detection, the attacker may attempt to persuade the victim to open the same file on a personal computer. The goal is to move the operation onto a device without the protections present in the organizational environment.

The Fake Application Is Built Around the Story

The lures are not uniform. The malicious application is selected to fit the narrative already presented to the target.

Observed samples have masqueraded as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. Another lure was presented as the result of an MRI scan.

The deception goes beyond the file name. After execution, the application can display an interface consistent with the expected software so the victim believes the intended program has opened normally. Meanwhile, the malware’s core components are deployed in the background.

One sample analyzed by the FBI, Pictory_premium_ver9.0.4.exe, masqueraded as a paid version of the Pictory AI video-generation service. It displayed a login screen and options for purchasing a subscription or starting a trial while extracting second-stage files and placing a component named smqdservice.exe on the device.

Another sample, Telegram_Authenticator.exe, presented itself as a Telegram authentication utility. Running it created a collection of files and a component named RuntimeSSH.exe. The apparently functional interface is therefore part of the social-engineering operation itself, extending the deception beyond the moment the target executes the file.

How HEAVYGRAM Survives a Windows Restart

Once execution succeeds, the next objective is to retain access to the machine. CHOSEN BRICK samples have primarily used the Windows Registry startup path:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Applications registered under this key can launch again when the same user signs in to Windows. The method also offers an operational advantage: adding an entry under this path does not necessarily require administrator privileges.

SMQDService and winappx are two malicious startup entries observed on compromised systems. Both components are also analyzed independently in the FBI’s HEAVYGRAM report, making them among the clearest technical links between the HEAVYGRAM and CHOSEN BRICK naming conventions.

Persistence is accompanied by efforts to reduce detection. Samples examined in the reports add directories to Microsoft Defender’s exclusion list, preventing the antivirus engine from scanning them. The FBI documented commands that excluded malware directories and, in some cases, Telegram’s download folder from Defender scans.

The operation therefore does not rely on file masquerading alone. Once access is established, Windows security settings can also be modified to reduce the likelihood that later components will be detected.

Telegram as Both a Lure and a Malware Control Channel

Telegram plays two distinct roles in the operation. It can first serve as the communications channel through which the attacker contacts the target. After infection, it can become part of the malware’s command-and-control infrastructure.

Compromised devices observed in the investigation connected to Telegram bots, with separate bot identifiers used for different infected systems. Commands could then be delivered to the malware through those channels.

The HEAVYGRAM code also contains direct requests to api.telegram.org and logic for receiving commands through Telegram bots. In one observed function, a file containing Chrome credential information was sent through this channel.

Telegram is not the only exfiltration route. Cloud-storage services including VultrObjects and StorjShare have also been used by this malware family to transfer files. Newer variants have used HTTPS and SOCKS5 proxies to obscure communications with Telegram bots.

The use of legitimate services creates an operational advantage: malicious traffic can blend into connections that may also have entirely normal uses. A connection to Telegram or a cloud-storage provider is therefore not, by itself, evidence of compromise and has to be evaluated alongside other indicators on the system.

What Can the Malware Access After Infection?

HEAVYGRAM’s capabilities show that the objective extends far beyond stealing a password. Documented functionality includes collecting system and process information, capturing screenshots, activating the microphone, collecting Telegram and WhatsApp data stored in the browser, stealing email, and downloading and executing additional files. File deletion has also been observed, and at least one sample contained functionality capable of wiping system data.

The FBI report provides additional detail on some of these capabilities. winappx.exe can collect data associated with the web versions of Telegram and WhatsApp from browser profiles. Other components are designed to extract browser information and Outlook email content. Collected material can be staged and compressed locally before it is sent out.

One sample contains a command named EnableMic, which downloads and executes a separate audio-recording component. That component can itself be configured for persistence so that it continues running after the user signs back into Windows.

The investigated toolset also contained code for identifying devices connected through the Media Transfer Protocol. This creates a path for accessing files on devices such as a mobile phone connected to the computer over USB.

Another finding involves Zoom calls. Data recovered from one sample included images of the victim during Zoom sessions alongside audio files. The associated code also contained functionality for capturing areas of the screen and handling microphone and speaker audio. The evidence indicates that, in some infections, collection could extend to the contents of voice and video calls.

A Compromised Computer Can Expose More Than Its Owner

The significance of the collected data is not limited to the personal files stored on a single machine. The joint advisory says screenshots and other collected material can be used to identify a victim’s contacts, location, and patterns of daily activity.

For a journalist, that access can expose information about confidential sources. For a dissident or activist, messages, email, and files may reveal the identities of people who were never directly targeted themselves.

A single compromised device can therefore become a source of intelligence on the wider network surrounding its owner. The joint advisory also says personal information belonging to previous CHOSEN BRICK victims has appeared on pro-Islamic Republic leak sites, potentially creating additional risks to their personal security.

In these cases, the operation does not necessarily end when information leaves the computer. Stolen material can later be published or used to maintain pressure on the victim.

Targeted at One Device, Not Designed to Spread Automatically

The joint advisory identifies an important limitation. In the samples observed, CHOSEN BRICK did not demonstrate automated lateral movement from one compromised computer to other systems on the same network. The operation remained focused on a specific device.

The malware can, however, download additional files and establish persistence for them. This allows operators to add new capabilities after initial access. The advisory notes that lateral movement could technically be enabled through additional tooling, but no such behavior was observed in the investigated samples.

That distinction matters. The available evidence supports the description of HEAVYGRAM as a targeted espionage toolset against specific systems, rather than malware designed to propagate automatically across a network.

Indicators Observed on Compromised Systems

The joint advisory provides several indicators that can assist with investigating a possible infection. SMQDService and winappx are among the names observed in Windows Registry startup entries.

Unexpected connections to api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net can also be examined alongside other evidence. None of these domains is independently proof of compromise, as they support legitimate services as well.

Two mutex values, ytyjyujyu and noi672pp434awkc12f, were also identified in samples from the malware family. The FBI’s HEAVYGRAM report additionally provides an extensive set of file hashes, installation paths, detection rules, and other technical indicators that can be used when examining suspected systems.

The HEAVYGRAM Attack Chain

Taken together, the two reports describe the operation as the following sequence:

Target reconnaissance ← messaging-app contact ← trust building ← malicious file or technical-assistance pretext ← execution or remote access ← HEAVYGRAM deployment ← Windows persistence ← Telegram bot communication ← collection of messages, email, audio, screenshots and files ← exfiltration ← use or publication of the stolen information

The first stage of the chain depends heavily on social engineering. In the documented cases, receiving a message by itself does not infect the computer. The target has to execute a file, install an application, or provide the access required by the attacker. This explains why prior research on the victim and a credible pretext are central to the operation.

After that point, the operation no longer depends on the victim’s cooperation. Persistent components can launch when the user returns to Windows, receive new commands, install additional tools, and prepare personal and communications data for exfiltration.

HEAVYGRAM Is Not a Single File

The FBI separates the samples it analyzed into first-stage masquerading applications, second-stage persistent implants, and additional components providing specialized capabilities. HEAVYGRAM therefore cannot be reduced to one executable file.

A fake application may only be the entry point. Another component preserves access, Telegram provides part of the command channel, cloud-storage services support data transfer, and separate modules can handle collection, audio recording, or file exfiltration. This architecture allows the operator to vary the deployed toolkit depending on the target.

Taken together, the September 15 reports provide a clearer picture of the operation. It begins before malware reaches the computer, with reconnaissance and the selection of a specific victim. It continues through trust-building and execution of a tailored lure. Once a device is compromised, it can become a source of intelligence not only about its owner, but also about that person’s communications, daily activity, and surrounding network.

The technical details also show how ordinary internet services can become part of an espionage chain. Telegram, AnyDesk, and cloud-storage platforms are not malicious in themselves. Combined with tailored fake applications, Windows persistence, security exclusions, and surveillance modules, however, they can form an infrastructure capable of maintaining long-term access to a specific target’s digital life.

Share: