HEAVYGRAM Spyware Targets Dissidents, Joint Advisory Warns
The FBI assesses that the operators act for Iran's Ministry of Intelligence and Security to gather intelligence, leak information and damage reputations. Its updated analysis covers seven malware samples and traces activity to autumn 2023. The separate joint advisory documents CHOSEN BRICK use since at least 2025.
According to the NCSC, attackers impersonate trusted contacts or technical support through messaging services, then persuade targets to open disguised software or files resembling MRI results. A convincing screen conceals installation. Attackers sometimes redirect victims to personal devices to evade workplace security controls.
The joint advisory says the malware persists through Windows registry Run keys and adds Microsoft Defender exclusions. Each infected device uses a separate Telegram bot for command and control. Capabilities include screenshots, microphone recording, email theft and downloading further malware. The agencies have not observed automatic movement between devices.
The NCSC warns that stolen information can expose victims' contacts, locations and routines; some personal details have appeared on pro-Iranian leak sites. It recommends that organizations investigate suspected infections and support checks of at-risk employees' personal devices. Its advisory supplies indicators and detection guidance.
The FBI urges defenders to use the indicators and detection signatures in its expanded analysis. It recommends current operating systems and software, enabled antivirus protection, unique passwords and multifactor authentication. Software should come from official stores or vendor sites, and suspicious communications should be reported. The FBI also advises reporting suspected crimes to its local field offices.