Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The FBI assesses that Iranian cyber actors are using HEAVYGRAM malware to conduct malicious cyber activity to target Iranian dissidents, journalists opposed to Iran, and other opposition groups around the world on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS).
The FBI calls it HEAVYGRAM, and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK. The malware is controlled via Telegram and can copy emails and chat messages, take screenshots, activate the microphone, steal credentials, download additional malware, and in at least one version wipe the computer.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
MOIS cyber actors used social engineering via social media platforms such as Telegram, WhatsApp, and Instagram to communicate with victims while offering IT services.
75 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows-focused Iranian intelligence espionage implant attributed by the FBI to Iran's Ministry of Intelligence and Security (MOIS). It is delivered through impersonation and trojanized-looking application files, establishes persistence through a Registry Run key, attempts to exclude its files from Microsoft Defender scanning, and uses a victim-specific Telegram bot for command-and-control and data exfiltration. Capabilities include surveillance, credential and email-address theft, file deletion, additional-payload download, and, in at least one variant, complete system wiping.
Windows-targeting espionage malware operated through per-victim Telegram bots. It uses masqueraded application installers and a fake user interface to install in the background, establishes persistence through Windows Run registry keys, excludes its files from Microsoft Defender scanning, and exfiltrates collected data through Telegram and cloud-storage services. It supports surveillance, credential and browser-data theft, command execution/download of further tools, file deletion, and potentially disk wiping.
Modular Windows surveillance and persistent-implant malware cluster delivered through social engineering. It uses Telegram as C2 and Vultr S3 for staging/exfiltration; it can conduct reconnaissance, execute commands, steal browser, Telegram, WhatsApp, and Outlook data, capture screenshots, access removable/MTP devices, and deploy further surveillance components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.