HEAVYGRAM, also tracked as CHOSEN BRICK, is a multi-stage Windows surveillance backdoor used in cyber-espionage activity targeting Iranian dissidents, anti-government journalists, activists, opposition organizations, and other individuals of interest to the Iranian government. The activity has operated since at least late 2023 and has been attributed by the FBI to cyber actors working for Iran's Ministry of Intelligence and Security (MOIS); reporting has linked the operation to the Handala Hack persona with moderate confidence. Operators commonly use trusted-contact and fake technical-support impersonation through messaging applications to induce victims to execute trojanized installers, documents, or other files masquerading as legitimate software.
The backdoor uses Telegram bots, accounts, and groups for host check-ins, command-and-control, payload delivery, and exfiltration. It supports arbitrary command execution, host, process, network, drive, and installed-software discovery; screenshot capture; microphone and audio recording; file collection; and deployment of further payloads. HEAVYGRAM can collect browser-held credentials and data, including communications and session-related data associated with Telegram and WhatsApp, and variants have collected email data and removable-device contents. It maintains persistence through Windows Registry autorun mechanisms and may reduce detection by creating Microsoft Defender exclusions, deleting files, and using DLL side-loading. At least one reported variant includes destructive system-wiping functionality. Its surveillance capabilities can expose victims' private communications, contacts, locations, professional sources, and routines, creating material operational and physical-security risks for targeted individuals.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AKSK publishes a technical analysis of HEAVYGRAM, also known as CHOSEN BRICK, used in cyber-espionage campaigns against activists and journalists in various countries. The analysis covers malicious execution and persistence mechanisms, Telegram-based command reception, C2 communications, malicious functions, and indicators of compromise.
Handala Hack is employing a sophisticated surveillance backdoor named HEAVYGRAM, which operates via Telegram.
The FBI calls it HEAVYGRAM, and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK. The malware is controlled via Telegram and can copy emails and chat messages, take screenshots, activate the microphone, steal credentials, download additional malware, and in at least one version wipe the computer.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
WSF/VBS scripts... run PowerShell cradles to download or write decoy files, and download/execute additional stages.
Prefix @@, to execute arbitrary system commands via os.popen.
Prefix @@ – used to execute arbitrary system commands via os.popen, returning command output directly to the Telegram command-and-control channel.
The WSF first stage contains obfuscated VBScript... before executing the encoded PowerShell. The executable contains base64-encoded data in an embedded resource.
CRUDEEXCLUDE ... prepares environments for HEAVYGRAM deployment by masquerading as legitimate applications.
Malware samples... facilitated... file deletion... The spoofed directory C:\Windows \SysWOW64\ and its contents are deleted.
HEAVYGRAM is ... capable of ... system and network information discovery.
pl – Enumerate running processes, including access-level information.
HEAVYGRAM is ... capable of ... system and network information discovery.
"HEAVYGRAM ... merr komanda përmes Telegram-it" (receives commands through Telegram).
“The malware uses Telegram bots, users, and groups for C2 and data exfiltration.”
181 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Telegram-based surveillance backdoor that executes remote commands; discovers system and network information; exfiltrates data; captures screenshots; establishes persistence through Windows Registry keys; and can execute secondary payloads.
A cyber-espionage malware implant that maintains persistence on compromised devices and communicates with command-and-control infrastructure, including receiving commands through Telegram.
Windows surveillance backdoor delivered through messaging-app lures impersonating legitimate programs. It supports screen capture, remote command execution, data exfiltration, persistence, and DLL sideloading, using Telegram bots, users, and groups for command-and-control and exfiltration.
A Python-based, Telegram C2 backdoor/implant used for surveillance and persistent access. It supports arbitrary command execution, host/network/process discovery, browser and saved-password theft, Telegram and WhatsApp data theft, screenshots, microphone activation, file transfer, secondary-payload download/execution, and file deletion. It evades defenses by excluding payload-staging paths from Microsoft Defender scanning and persists through Windows autorun Registry keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.