Iranian MOIS Deploys CHOSEN BRICK Malware to Spy on Dissidents

By CyberNewsAI AdminVERIFIED INTEL
Surveillance silhouette displaying Windows and browser surveillance telemetry representing Iranian CHOSEN BRICK malware campaign

SOC Briefing Summary :: Executive Key Takeaways

  • [01]A joint advisory from the UK NCSC, US FBI, and Dutch AIVD exposes CHOSEN BRICK (tracked by the FBI as HEAVYGRAM), an Iranian MOIS surveillance malware active since autumn 2023.
  • [02]Threat actors use targeted social engineering across WhatsApp and Telegram to deliver disguised Windows payloads (e.g. Pictory, KeePass, MRI scans) controlled via dedicated Telegram bots.
  • [03]The spyware harvests browser tokens, captures screenshots and microphone audio, exfiltrates data via cloud object stores, and possesses data-wiping modules for target suppression.
SHARE INTEL:Reddit

A coordinated international cybersecurity advisory published jointly by the United Kingdom's National Cyber Security Centre (NCSC), the United States Federal Bureau of Investigation (FBI), and the Netherlands' General Intelligence and Security Service (AIVD) has exposed a widespread cyber espionage campaign conducted by Iran's Ministry of Intelligence and Security (MOIS).

Active since at least autumn 2023, the campaign deploys a sophisticated Windows spyware ecosystem tracked as CHOSEN BRICK by the NCSC and HEAVYGRAM by the FBI. The operations specifically target Iranian dissidents, human rights defenders, anti-regime activists, and independent journalists located across the United Kingdom, the United States, the Netherlands, and internationally. Allied intelligence agencies warn that this digital surveillance feeds directly into physical intelligence operations, enabling state actors to track targets' daily movements, harass associates, leak stolen identities, and coordinate physical threats abroad.

Technical Analysis

The CHOSEN BRICK malware framework pairs patient, customized social engineering with a multi-stage persistence and remote control architecture that weaponizes consumer communication platforms:

Social Engineering & Delivery Vectors

Adversaries engage targets through social messaging services—primarily WhatsApp and Telegram—establishing trust over days or weeks before transmitting weaponized files:

  • Impersonation & Rapport Building (T1589, T1566.003): Threat actors pose as trusted acquaintances, journalistic contacts, or platform technical support representatives. They frequently initiate contact on corporate or work-associated devices, pivoting to victims' unmanaged personal computers if corporate endpoint controls flag the files.
  • Deceptive File Lures (T1204.002): Payloads are tailored to match ongoing conversations, masquerading as legitimate Windows programs such as Pictory (an AI video tool), RunwayML, KeePass, Telegram desktop installers, Norton Antivirus, Adobe Flash Player, or medical MRI scan archives.
  • Deceptive Decoy Screens: Upon initial user execution, the binary displays a convincing splash screen corresponding to the spoofed application while silently executing the primary spyware loader in the background.

Persistence, Evasion, and Telegram C2

CHOSEN BRICK is engineered to maintain persistent access exclusively on Microsoft Windows operating systems:

  • User-Level Registry Persistence (T1547.001): To survive system reboots without requiring elevated administrative privileges, the malware registers values under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Observed registry value names include SMQDService (pointing to executables in C:\ProgramData\SMQDServicePackages\) and winappx (pointing to C:\Users\All Users\MicrosoftDistribution\sysmain\winappx.exe).
  • Antivirus Evasion & Execution Guardrails (T1480.002, T1685): The implant dynamically registers mutexes (such as ytyjyujyu or noi672pp434awkc12f) to avoid duplicate executions. It also injects directory exclusions directly into Microsoft Defender to shield its staging directories.
  • Dedicated Telegram Bot C2 Channels (T1102.002): For command and control, each infected endpoint connects to a distinct, dedicated Telegram Bot token. This operational security measure isolates victims from one another, preventing forensic cross-contamination should a single bot token be seized or identified.
  • Stealth Staging Directory: When instructed to stage additional binaries, the malware frequently deploys files into an artificially created path at C:\Windows \SysWOW64 (leveraging a trailing space after the Windows folder name to evade casual inspection).

Real-Time Surveillance & Destructive Capabilities

The spyware suite possesses an expansive operational toolset executed via Telegram commands and native Windows utilities:

  • Audio & Visual Surveillance (T1113, T1123): Operates continuous desktop screenshot captures and silently enables host microphones to intercept room acoustics and private conversations.
  • Browser Token & Messaging Scraping (T1005): Extracts saved session tokens, cookies, and local database storage for web-based versions of Telegram and WhatsApp directly from browser directories.
  • Email & Process Harvesting (T1057, T1082, T1114.001): Enumerates running system tasks, hardware properties, network interfaces, and unencrypted local email caches.
  • Data Wiping & Destruction (T1485): In at least one analyzed variant, developers integrated a disk-wiping routine capable of purging master file structures or selectively deleting files to sabotage victim systems upon discovery.
  • Decentralized Exfiltration (T1041, T1567.002, T1090.002): Stolen archives are exfiltrated either directly through the Telegram Bot API or routed to cloud storage object buckets, including VultrObjects, StorjShare, and Backblaze B2. Recent iterations route bot traffic through commercial residential proxies (IPRoyal, LightningProxies) to bypass egress filtering.

Attack Vector & Impact

The campaign represents a severe hybrid threat where state-sponsored cyber operations directly support extraterritorial physical repression:

  • State Intelligence Attribution: The FBI and allied services assess with high confidence that the operators belong to Iran's Ministry of Intelligence and Security (MOIS), representing a dedicated effort to suppress domestic dissent projected overseas.
  • Physical Safety Hazards: Stolen daily calendars, contacts, real-time screenshots, and location data have appeared on pro-Iranian doxxing and leak platforms. Western intelligence agencies highlight that MOIS elements have previously plotted physical abductions and lethal attacks against dissident figures targeted by these same surveillance apparatuses.
  • Corporate-to-Personal Pivot: Because operators actively encourage targets to transition suspicious files to personal laptops, corporate security teams face lateral identity risks where corporate credentials, tokens, and communications are harvested from unmanaged home devices.

Detection & Mitigation

Organizations employing personnel of interest—as well as at-risk individuals—must implement layered forensic hunting and behavioral defenses:

Forensic Threat Hunting & Endpoint Indicators

  • Registry Run Key Inspection: Query the current user Run key via PowerShell (reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Run") to verify that unverified binaries such as smdqservice.exe or winappx.exe are not configured to execute at login.
  • Anomalous Directory Auditing: Search endpoints for non-standard folder structures featuring anomalous whitespace manipulation, particularly C:\Windows \SysWOW64.
  • Mutex Scanning: Configure endpoint detection rules to alert on the presence of mutex strings ytyjyujyu and noi672pp434awkc12f.
  • Proxy and Cloud Object Egress: Monitor corporate proxy and DNS logs for unauthorized connections originating from non-browser processes to api.telegram.org, vultrobjects.com, storjshare.io, backblazeb2.com, iproyal.com, and lightningproxies.net.

Defensive Hardening Recommendations

  • Phishing-Resistant MFA: Enforce FIDO2 / WebAuthn hardware security keys for corporate and personal email and messaging accounts, ensuring that stolen session tokens or credentials cannot be reused without physical authenticator prompts.
  • Application Allowlisting: Enforce software restriction policies (AppLocker or Windows Defender Application Control) on corporate and managed devices to block the execution of unauthorized binaries in user-writable directories.
  • Social Engineering Awareness: Educate high-risk journalists, researchers, and dissidents regarding persona-based lure tactics, emphasizing that trusted contacts or tech support personas should never be permitted to deliver software installers via direct messaging channels.
Indicators of Compromise (IOCs)
17 Identified
threat_actorIranian Ministry of Intelligence and Security (MOIS)
malwareCHOSEN BRICK / HEAVYGRAM
registryHKCU\Software\Microsoft\Windows\CurrentVersion\Run
mutexytyjyujyu
mutexnoi672pp434awkc12f
domainapi.telegram.org
domainvultrobjects.com
domainstorjshare.io
domainbackblazeb2.com
domainiproyal.com
domainlightningproxies.net
mitre_attackT1566.003
mitre_attackT1102.002
mitre_attackT1547.001
mitre_attackT1113
mitre_attackT1123
mitre_attackT1485
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE