Skip to main content
← Back to Demos
Malware intermediate · 15 min

FBI, NCSC and AIVD Expose Iran's HEAVYGRAM: Telegram-Controlled Spyware Built to Target Dissidents and Journalists — Sandbox Detonates the Screen-Capture Stage (2026-09-16 CISO Daily Digest)

The 2026-09-16 CISO Daily Digest covered the September 15 joint advisory from the FBI, the UK's NCSC and the Netherlands' AIVD exposing a Windows spyware — called HEAVYGRAM by the FBI and CHOSEN BRICK by the NCSC — that Iran's Ministry of Intelligence and Security (MOIS) uses to spy on dissidents, journalists and activists around the world. The implant is controlled through a per-victim Telegram bot: the agencies say it can copy a target's emails and chat messages, take screenshots, activate the microphone to record audio, steal saved passwords and browser data, and download more tools — exfiltrating what it collects through the Telegram channel and cloud services (Vultr, Storj), with newer versions routing Telegram traffic through proxies to blend into normal activity. Entry begins with a message posing as a known contact or as tech support for a messaging app; the agencies say attackers often target the work computer first and pivot to an unprotected personal device if that fails, and reported disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton and Adobe Flash Player — in some cases files were made to look like MRI scan results. The campaign dates to autumn 2023 and, the advisory says, has been used against people in the UK, U.S. and Netherlands, and worldwide, since at least 2025; it notes victims' personal details have appeared on pro-Iranian leak sites, raising risks beyond data theft. Its detection guidance lists a Run-key entry (SMQDService or winappx) for login persistence, a spoofed drop path (C:\Windows \SysWOW64 — note the added space), Microsoft Defender folder exclusions, and unexpected connections to otherwise legitimate services including api.telegram.org, vultrobjects.com and storjshare.io. This demo safely reproduces the payload-behavior stage of that intrusion: malicious-payload.sh stages a screen-capture artifact (./exfil/screen.png, a placeholder stand-in for the spyware's screen-grabbing capability) and then opens the Calculator as its only visible impact — no real screen content is captured, nothing is exfiltrated, no network contact, nothing destructive; malicious-win.cmd reproduces the same impact for Windows hosts; the clean control sample (clean-payload.sh) has the attack sequence removed and opens nothing. MetaDefender Sandbox detonates the sample in an isolated environment, observes the screen-capture / staging behavior, and reports the spyware's activity with behavioral indicators — no signature required (MITRE ATT&CK T1113 — Screen Capture).

Attack Technique

Telegram-bot-controlled espionage implant (FBI/NCSC/AIVD joint advisory: HEAVYGRAM / CHOSEN BRICK, attributed to Iran's MOIS; active since autumn 2023) — sandbox detonation of the screen-capture stage demonstrates spyware screen-grabbing behavior (T1113 Screen Capture)

MITRE ATT&CK

T1113 ↗

Platforms

linux

File Types

.cmd.sh

MetaDefender Capabilities

MetaDefender Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---