Originally published on the RelayShield blog.
On September 15, three agencies — the FBI, the U.K.'s National Cyber Security Center, and the Netherlands' AIVD — published a joint advisory about a Windows malware family controlled entirely through the Telegram messaging app. The FBI calls it HEAVYGRAM; the NCSC calls it CHOSEN BRICK. The FBI attributes it to Iran's Ministry of Intelligence and Security, and dates the wider campaign to the autumn of 2023. It has been used against people in the U.K., the U.S., and the Netherlands since at least 2025.
The targets are mainly Iranian dissidents, journalists, and activists — but the FBI warns that anyone Iran considers of interest could be a target. Stolen personal details have appeared on pro-Iranian leak sites, and in March the U.S. Justice Department seized four such sites that posted stolen data and called for the killing of dissidents and journalists.
How it works
Every stage of the attack runs through messaging. It begins with a message: the operators pose as someone the target knows, or as tech support for a messaging app, and build trust before sending a file that looks like a legitimate program. Reported disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus, Adobe Flash Player — in some cases even files dressed up to look like MRI scan results. The operators usually start on the victim's work computer, and move to a personal device if that fails.
Opening the file shows a convincing fake screen while the malware installs in the background. A second stage then connects the computer to a Telegram bot that the operators use to control it and collect stolen data. Each infected computer gets its own Telegram bot, keeping victims' data separate.
To survive a restart, the malware adds itself to a Windows "Run" registry key — reported names include SMQDService and winappx — and tells Microsoft Defender to skip the folders where it hides. Then it waits for commands. The capabilities are broad: list running programs, take screenshots, switch on the microphone, copy Telegram and WhatsApp data out of the browser, steal saved passwords and email addresses, download more malware, delete files. At least one version can wipe the computer entirely.
Exfiltrated data leaves through the victim's Telegram bot and through cloud storage services such as Vultr and Storj. Newer versions route Telegram traffic through proxy servers to make the command-and-control harder to spot.
Why this matters for Telegram watchers
This campaign is a reminder of something RelayShield's monitoring exists for: the same platform that carries scams and phishing lures also serves as infrastructure for targeted operations. Malicious Telegram bots and the domains tied to them are exactly the kind of infrastructure our bots watch across monitored Telegram marketplaces and our threat-intel corpus, and the indicators in advisories like this one — registry names, mutex markers, network destinations — are the artifacts a corpus is built to track. When a campaign like this is confirmed, the IOCs feed the same free check tools our readers already use: run an unfamiliar download link, domain, or crypto wallet through the free checks before trusting it.
One concrete takeaway
Do not open files sent through messages — not from strangers, and not from contacts who were recently "hacked" without a good reason. Download software only from official websites and app stores, and if an app asks you to install something from a chat, treat that as the attack. HEAVYGRAM's entire first stage depended on one click on one file in one message. Every operator in this business knows that, which is why they keep sending them.
Sources: joint advisory published September 15 by the FBI, U.K. NCSC, and Dutch AIVD; FBI updated analysis of HEAVYGRAM; reporting via The Hacker News, September 2026. No incident details in this post beyond what those sources document.
Top comments (0)