Campaigns
CHOSEN BRICK / HEAVYGRAM: Iranian State Surveillance Campaign Targeting Dissidents, Activists, and Journalists

CHOSEN BRICK / HEAVYGRAM: Iranian State Surveillance Campaign Targeting Dissidents, Activists, and Journalists

IranNation-State EspionageCHOSEN BRICKTelegram C2Transnational Repression
CHOSEN BRICK (FBI: HEAVYGRAM) is Windows surveillance malware used by Iranian MOIS-linked actors to spy on dissidents, activists, and journalists. Operators pose as trusted contacts or support staff on WhatsApp, Telegram, and Instagram, then deliver payloads disguised as legitimate apps or MRI results. The implant steals email, Telegram/WhatsApp sessions, screenshots, mic audio, and browser credentials via Telegram bot APIs and cloud storage. Since the data ends up on pro-Iranian leak sites, infections pose a physical safety risk, not just a data breach.

Indicators of Compromise

iproyal.com
vultrobjects.com
storjshare.io
lightningproxies.net
backblazeb2.com

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION
DETECTION

Technique

Name

Detection Strategy

Detection and Remediation Guidance

T1589 (Gather Victim Identity Information)

Gather Victim Identity Information

DET0841

Not detectable on the endpoint. Monitor for reconnaissance signals reported by at-risk staff, including unsolicited contact referencing accurate personal detail.

T1566.003 (Spearphishing via Service)

Spearphishing via Service

DET0115

Correlate messaging-platform file drops with subsequent process creation. Files written to %USERPROFILE%\Downloads\Telegram Desktop\ followed by execution of an unsigned PE are the highest-fidelity entry signal.

T1204.002 (Malicious File)

User Execution: Malicious File

DET0294

Alert on Delphi or PyInstaller-packed executables launched from user download directories that spawn powershell.exe or cmd.exe within seconds of first execution.

T1547.001 (Registry Run Keys / Startup Folder)

Registry Run Keys / Startup Folder

DET0365

Query HKCU\Software\Microsoft\Windows\CurrentVersion\Run for the value names SMQDService, winappx, Default_SSH, and MicDriver. Run "reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run" across the estate and diff against a known-good baseline. Value names are mutable, so treat any Run entry pointing into C:\ProgramData as suspicious.

T1480.002 (Mutual Exclusion)

Execution Guardrails: Mutual Exclusion

DET0132

Hunt for creation of the mutexes ytyjyujyu, noi672pp434awkc12f, euyrsmnszb85sf4444s, and nih6723443489kcvrf. These are hardcoded and are among the most durable indicators available.

T1685 (Disable or Modify Tools)

Disable or Modify Tools

DET0497

Alert on any Add-MpPreference ExclusionPath or ExclusionExtension event, and specifically on exclusions covering C:\ProgramData\MicrosoftDistribution\sysmain, C:\ProgramData\SMQDServicePackages\488ht1-8ww648q, and the Telegram Desktop downloads folder. Review existing exclusion lists as a compromise assessment step.

T1059.001 (PowerShell)

Command and Scripting Interpreter: PowerShell

DET0455

Script block logging on pwsh.exe and powershell.exe invoked with -Command by a non-shell parent process. Also alert on Invoke-WebRequest calls whose URI resolves to object-storage hosts.

T1057 (Process Discovery)

Process Discovery

DET0034

Correlate psutil-driven process enumeration with immediate write of an encrypted .Dat file into C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s.

T1082 (System Information Discovery)

System Information Discovery

DET0525

Alert on systeminfo execution by a Python-packed parent process, followed by a Si*.Dat file write in the staging directory.

T1083 (File and Directory Discovery)

File and Directory Discovery

DET0370

Detect recursive enumeration across drive letters A through K, which is the fixed enumeration range implemented by the implant, followed by an LF*.Dat write.

T1112 (Modify Registry)

Modify Registry

DET0280

Monitor HKCU Run key writes originating from processes located under C:\ProgramData or from PyInstaller-packed binaries.

T1113 (Screen Capture)

Screen Capture

DET0346

Hunt for SN_*.Dat files in the staging directory and for JPEG writes matching C:\ProgramData\Drivers\MicDriver\_*.jpeg. Periodic screenshot capture is configurable through the SnapTime token, with a 10-second default interval in the recorder module.

T1123 (Audio Capture)

Audio Capture

DET0221

Detect WASAPI session enumeration by unsigned binaries and hunt for _*_mic.wav and _*_spk.wav files under C:\ProgramData\Drivers\MicDriver. The module activates on Zoom session detection.

T1056.001 (Keylogging)

Input Capture: Keylogging

DET0089

A keylogger thread is created from configuration, though the underlying KeyLog function is unimplemented in the analyzed samples. Monitor pynput-based hook installation in case the capability is completed in future builds. Flagged as present but non-functional.

T1005 (Data from Local System)

Data from Local System

DET0380

Alert on bulk file creation in C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s. Every collection function in the implant funnels into this single directory, which makes it the most efficient single detection anchor in the campaign.

T1025 (Data from Removable Media)

Data from Removable Media

DET0511

Detect Media Transfer Protocol device enumeration followed by writes to ...\Z84A847FEEB1FC2s\Files\Phones\. The implant copies connected phone and USB content automatically.

T1114.001 (Local Email Collection)

Email Collection: Local Email Collection

DET0047

Monitor Outlook COM automation by non-Office processes enumerating Inbox, Sent Items, Deleted Items, Archive, and Junk Email folders, and hunt for OU*.zip archives in the staging directory.

T1555.003 (Credentials from Web Browsers)

Credentials from Web Browsers

DET0037

Alert on access to %LOCALAPPDATA%\Google\Chrome\User Data\Local State and Login Data by non-browser processes, on CryptUnprotectData usage, and on the artifacts ChromePasswordsBackup.db and chrome_passwords.json.

T1539 (Steal Web Session Cookie)

Steal Web Session Cookie

DET0509

Detect compression of https_web.whatsapp.com_0.indexeddb.leveldb and https_web.telegram.org_0.indexeddb.leveldb, and of Local Storage directories, into Z-*.Dat files. Session theft survives password resets, so force session revocation during remediation.

T1528 (Steal Application Access Token)

Steal Application Access Token

DET0515

Review Google account OAuth grants for unexpected applications requesting full mail scope. Hunt for *.pickle files and credentials.json in C:\ProgramData\ZlibDate\CachedFiles, and for headless Chrome sessions using the static user-agent string referenced in the IoCs section.

T1560.001 (Archive via Utility)

Archive Collected Data: Archive via Utility

DET0298

Alert on Rar.exe execution with the -p password switch, in particular the observed argument pattern including -pLoLoLoLo, and on multi-volume RAR parts under C:\ProgramData\ZlibDate\Z84A847FEEB1FC2s\Records.

T1027 (Obfuscated Files or Information)

Obfuscated Files or Information

DET0378

Hunt for the filename rantom.txt anywhere on disk. This encrypted blob holds the implant command implementations and is decrypted only at runtime, so its presence alongside a Python interpreter bundle is a strong signal.

T1036.005 (Match Legitimate Resource Name or Location)

Masquerading: Match Legitimate Resource Name or Location

DET0347

Detect the non-standard directory "C:\Windows " with a trailing space, and any process image path under "C:\Windows \SysWOW64", including bthudtask.exe. Also flag WhatssApp.exe with the doubled letter S and shortcut modifications pointing to it.

T1553.002 (Code Signing)

Subvert Trust Controls: Code Signing

DET0230

Enforce certificate revocation checking. Alert on execution of binaries whose signing certificate is revoked, which covers the observed SSL.com-signed winappx.exe variant.

T1105 (Ingress Tool Transfer)

Ingress Tool Transfer

DET0060

Detect downloads of MicDriver.zip, WhatssApp.exe, WebView2Loader.dll, MSCache.exe, and credentials.json from Vultr Objects buckets into C:\ProgramData\ZlibDate\CachedFiles.

T1102.002 (Bidirectional Communication)

Web Service: Bidirectional Communication

DET0035

Baseline and alert on api.telegram.org traffic from non-Telegram processes. Each victim is assigned a unique bot ID, so hunt on the destination and the calling process rather than on a shared C2 identifier.

T1041 (Exfiltration Over C2 Channel)

Exfiltration Over C2 Channel

DET0348

Monitor for repeated POST requests to api.telegram.org endpoints including sendDocument and sendPhoto, and for outbound GET requests to api.ipify.org used as a victim IP lookup.

T1567.002 (Exfiltration to Cloud Storage)

Exfiltration to Cloud Storage

DET0570

Alert on S3-compatible PUT traffic to ams1.vultrobjects.com and sgp1.vultrobjects.com, on the bucket-name substring -ppmppnf12uyt4r5tifjdfh-, and on unexpected traffic to storjshare.io and backblazeb2.com.

T1090.002 (External Proxy)

Proxy: External Proxy

DET0325

Investigate unexpected connections to iproyal.com and lightningproxies.net. Newer variants relay Telegram traffic through HTTPS and SOCKS5 proxies specifically to defeat destination-based detection.

T1485 (Data Destruction)

Data Destruction

DET0146

Alert on mass file deletion by user-context Python processes. Host wipe is an operator-triggered command rather than an automatic behavior, so this detection is a last-resort control.

Observed Countries250

AD (781)
AE (521)
AF (250)
AG (573)
AI (809)
AL (333)
AM (373)
AO (863)
AQ (965)
AR (650)
AS (195)
AT (784)
AU (105)
AW (734)
AX (101)
AZ (691)
BA (233)
BB (632)
BD (276)
BE (726)
BF (179)
BG (860)
BH (646)
BI (13)
BJ (367)
BL (427)
BM (859)
BN (16)
BO (345)
BQ (623)
BR (44)
BS (432)
BT (94)
BV (331)
BW (1)
BY (821)
BZ (193)
CA (183)
CC (518)
CD (644)
CF (513)
CG (114)
CH (954)
CI (232)
CK (113)
CL (534)
CM (552)
CN (514)
CO (623)
CR (856)
CU (382)
CV (569)
CW (475)
CX (249)
CY (894)
CZ (690)
DE (924)
DJ (1)
DK (612)
DM (599)
DO (764)
DZ (730)
EC (99)
EE (10)
EG (285)
EH (885)
ER (266)
ES (265)
ET (446)
FI (302)
FJ (745)
FK (814)
FM (444)
FO (822)
FR (895)
GA (389)
GB (337)
GD (486)
GE (79)
GF (967)
GG (596)
GH (807)
GI (240)
GL (911)
GM (966)
GN (22)
GP (595)
GQ (279)
GR (594)
GS (353)
GT (444)
GU (850)
GW (91)
GY (770)
HK (468)
HM (328)
HN (451)
HR (729)
HT (459)
HU (164)
ID (728)
IE (689)
IL (381)
IM (217)
IN (238)
IO (888)
IQ (928)
IR (387)
IS (966)
IT (913)
JE (257)
JM (170)
JO (338)
JP (317)
KE (517)
KG (876)
KH (30)
KI (193)
KM (935)
KN (712)
KP (63)
KR (486)
KW (791)
KY (261)
KZ (23)
LA (89)
LB (911)
LC (339)
LI (611)
LK (395)
LR (742)
LS (925)
LT (987)
LU (772)
LV (110)
LY (798)
MA (511)
MC (347)
MD (945)
ME (754)
MF (275)
MG (107)
MH (873)
MK (731)
ML (949)
MM (808)
MN (665)
MO (919)
MP (676)
MQ (290)
MR (619)
MS (383)
MT (360)
MU (809)
MV (336)
MW (155)
MX (899)
MY (14)
MZ (574)
NA (167)
NC (380)
NE (84)
NF (186)
NG (69)
NI (120)
NL (104)
NO (66)
NP (235)
NR (356)
NU (881)
NZ (703)
OM (549)
PA (869)
PE (477)
PF (877)
PG (292)
PH (884)
PK (495)
PL (187)
PM (315)
PN (206)
PR (184)
PS (390)
PT (374)
PW (814)
PY (527)
QA (472)
RE (738)
RO (305)
RS (465)
RU (450)
RW (868)
SA (115)
SB (842)
SC (806)
SD (915)
SE (215)
SG (747)
SH (666)
SI (716)
SJ (779)
SK (984)
SL (887)
SM (523)
SN (241)
SO (577)
SR (477)
SS (545)
ST (481)
SV (496)
SX (622)
SY (477)
SZ (960)
TC (784)
TD (541)
TF (413)
TG (772)
TH (562)
TJ (44)
TK (134)
TL (197)
TM (756)
TN (489)
TO (483)
TR (876)
TT (908)
TV (933)
TW (790)
TZ (106)
UA (298)
UG (288)
UM (249)
US (89)
UY (165)
UZ (828)
VA (632)
VC (983)
VE (603)
VG (331)
VI (273)
VN (595)
VU (72)
WF (982)
WS (456)
XK (973)
YE (769)
YT (214)
ZA (804)
ZM (565)
ZW (258)