
CHOSEN BRICK / HEAVYGRAM: Iranian State Surveillance Campaign Targeting Dissidents, Activists, and Journalists
Indicators of Compromise
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Technique | Name | Detection Strategy | Detection and Remediation Guidance |
Gather Victim Identity Information | Not detectable on the endpoint. Monitor for reconnaissance signals reported by at-risk staff, including unsolicited contact referencing accurate personal detail. | ||
Spearphishing via Service | Correlate messaging-platform file drops with subsequent process creation. Files written to %USERPROFILE%\Downloads\Telegram Desktop\ followed by execution of an unsigned PE are the highest-fidelity entry signal. | ||
User Execution: Malicious File | Alert on Delphi or PyInstaller-packed executables launched from user download directories that spawn powershell.exe or cmd.exe within seconds of first execution. | ||
Registry Run Keys / Startup Folder | Query HKCU\Software\Microsoft\Windows\CurrentVersion\Run for the value names SMQDService, winappx, Default_SSH, and MicDriver. Run "reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run" across the estate and diff against a known-good baseline. Value names are mutable, so treat any Run entry pointing into C:\ProgramData as suspicious. | ||
Execution Guardrails: Mutual Exclusion | Hunt for creation of the mutexes ytyjyujyu, noi672pp434awkc12f, euyrsmnszb85sf4444s, and nih6723443489kcvrf. These are hardcoded and are among the most durable indicators available. | ||
Disable or Modify Tools | Alert on any Add-MpPreference ExclusionPath or ExclusionExtension event, and specifically on exclusions covering C:\ProgramData\MicrosoftDistribution\sysmain, C:\ProgramData\SMQDServicePackages\488ht1-8ww648q, and the Telegram Desktop downloads folder. Review existing exclusion lists as a compromise assessment step. | ||
Command and Scripting Interpreter: PowerShell | Script block logging on pwsh.exe and powershell.exe invoked with -Command by a non-shell parent process. Also alert on Invoke-WebRequest calls whose URI resolves to object-storage hosts. | ||
Process Discovery | Correlate psutil-driven process enumeration with immediate write of an encrypted .Dat file into C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s. | ||
System Information Discovery | Alert on systeminfo execution by a Python-packed parent process, followed by a Si*.Dat file write in the staging directory. | ||
File and Directory Discovery | Detect recursive enumeration across drive letters A through K, which is the fixed enumeration range implemented by the implant, followed by an LF*.Dat write. | ||
Modify Registry | Monitor HKCU Run key writes originating from processes located under C:\ProgramData or from PyInstaller-packed binaries. | ||
Screen Capture | Hunt for SN_*.Dat files in the staging directory and for JPEG writes matching C:\ProgramData\Drivers\MicDriver\_*.jpeg. Periodic screenshot capture is configurable through the SnapTime token, with a 10-second default interval in the recorder module. | ||
Audio Capture | Detect WASAPI session enumeration by unsigned binaries and hunt for _*_mic.wav and _*_spk.wav files under C:\ProgramData\Drivers\MicDriver. The module activates on Zoom session detection. | ||
Input Capture: Keylogging | A keylogger thread is created from configuration, though the underlying KeyLog function is unimplemented in the analyzed samples. Monitor pynput-based hook installation in case the capability is completed in future builds. Flagged as present but non-functional. | ||
Data from Local System | Alert on bulk file creation in C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s. Every collection function in the implant funnels into this single directory, which makes it the most efficient single detection anchor in the campaign. | ||
Data from Removable Media | Detect Media Transfer Protocol device enumeration followed by writes to ...\Z84A847FEEB1FC2s\Files\Phones\. The implant copies connected phone and USB content automatically. | ||
Email Collection: Local Email Collection | Monitor Outlook COM automation by non-Office processes enumerating Inbox, Sent Items, Deleted Items, Archive, and Junk Email folders, and hunt for OU*.zip archives in the staging directory. | ||
Credentials from Web Browsers | Alert on access to %LOCALAPPDATA%\Google\Chrome\User Data\Local State and Login Data by non-browser processes, on CryptUnprotectData usage, and on the artifacts ChromePasswordsBackup.db and chrome_passwords.json. | ||
Steal Web Session Cookie | Detect compression of https_web.whatsapp.com_0.indexeddb.leveldb and https_web.telegram.org_0.indexeddb.leveldb, and of Local Storage directories, into Z-*.Dat files. Session theft survives password resets, so force session revocation during remediation. | ||
Steal Application Access Token | Review Google account OAuth grants for unexpected applications requesting full mail scope. Hunt for *.pickle files and credentials.json in C:\ProgramData\ZlibDate\CachedFiles, and for headless Chrome sessions using the static user-agent string referenced in the IoCs section. | ||
Archive Collected Data: Archive via Utility | Alert on Rar.exe execution with the -p password switch, in particular the observed argument pattern including -pLoLoLoLo, and on multi-volume RAR parts under C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s\Records. | ||
Obfuscated Files or Information | Hunt for the filename rantom.txt anywhere on disk. This encrypted blob holds the implant command implementations and is decrypted only at runtime, so its presence alongside a Python interpreter bundle is a strong signal. | ||
Masquerading: Match Legitimate Resource Name or Location | Detect the non-standard directory "C:\Windows " with a trailing space, and any process image path under "C:\Windows \SysWOW64", including bthudtask.exe. Also flag WhatssApp.exe with the doubled letter S and shortcut modifications pointing to it. | ||
Subvert Trust Controls: Code Signing | Enforce certificate revocation checking. Alert on execution of binaries whose signing certificate is revoked, which covers the observed SSL.com-signed winappx.exe variant. | ||
Ingress Tool Transfer | Detect downloads of MicDriver.zip, WhatssApp.exe, WebView2Loader.dll, MSCache.exe, and credentials.json from Vultr Objects buckets into C:\ProgramData\ZlibDate\CachedFiles. | ||
Web Service: Bidirectional Communication | Baseline and alert on api.telegram.org traffic from non-Telegram processes. Each victim is assigned a unique bot ID, so hunt on the destination and the calling process rather than on a shared C2 identifier. | ||
Exfiltration Over C2 Channel | Monitor for repeated POST requests to api.telegram.org endpoints including sendDocument and sendPhoto, and for outbound GET requests to api.ipify.org used as a victim IP lookup. | ||
Exfiltration to Cloud Storage | Alert on S3-compatible PUT traffic to ams1.vultrobjects.com and sgp1.vultrobjects.com, on the bucket-name substring -ppmppnf12uyt4r5tifjdfh-, and on unexpected traffic to storjshare.io and backblazeb2.com. | ||
Proxy: External Proxy | Investigate unexpected connections to iproyal.com and lightningproxies.net. Newer variants relay Telegram traffic through HTTPS and SOCKS5 proxies specifically to defeat destination-based detection. | ||
Data Destruction | Alert on mass file deletion by user-context Python processes. Host wipe is an operator-triggered command rather than an automatic behavior, so this detection is a last-resort control. |