Skip to content

HEAVYGRAM

HEAVYGRAM, also tracked as CHOSEN BRICK by the UK National Cyber Security Centre, is a modular Windows surveillance backdoor used in campaigns against Iranian dissidents, journalists, activists, opposition organizations, and other persons of interest to the Iranian government.

Profile source: Mallory opens in a new tab

HEAVYGRAM

Family profile

HEAVYGRAM, also tracked as CHOSEN BRICK by the UK National Cyber Security Centre, is a modular Windows surveillance backdoor used in campaigns against Iranian dissidents, journalists, activists, opposition organizations, and other persons of interest to the Iranian government. Activity has been observed since autumn 2023. The FBI attributes its use to cyber actors operating for Iran's Ministry of Intelligence and Security (MOIS); it is also attributed with moderate confidence to the Handala Hack persona, assessed by multiple researchers as linked to Void Manticore.

HEAVYGRAM uses Telegram bots, accounts, and groups for command-and-control, tasking, payload delivery, host check-ins, and data exfiltration. It supports arbitrary command execution, host, process, application, drive, and file discovery; screenshot and audio capture; collection of removable-device data; and execution of additional payloads. It can collect browser profile data, stored credentials, messaging data and session material associated with Telegram and WhatsApp, Telegram Desktop data, and email data. Some components support collection from Outlook and Gmail. The malware can download and run secondary payloads, remove files, and at least one reported variant can wipe a compromised system.

The backdoor maintains persistence through Windows Registry autorun entries and employs defense evasion including Microsoft Defender exclusion configuration and DLL sideloading. Operators use tailored social engineering through messaging applications, impersonating trusted contacts or technical-support personnel and distributing trojanized installers, documents, media, scripts, and archive-based payloads masquerading as legitimate software or services. Decoy interfaces may be displayed while malicious components install in the background. Associated CRUDEEXCLUDE tooling can prepare victim hosts by creating staging locations and adding Microsoft Defender exclusions before later payload deployment.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 18, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
0 IP / 5 hostnames

Leading locations

  • NL1
  • SG1

Leading providers

  • The Constant Company, LLC2

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

3 named in public reporting
Handala

HEAVYGRAM is a Windows backdoor attributed with moderate confidence to Handala Hack, used since 2023 to target Iranian dissidents, journalists, and individuals opposing the Iranian government.

MOIS

The FBI calls the Windows malware HEAVYGRAM, while the UK NCSC calls it CHOSEN BRICK. It is controlled through Telegram and can copy email and chat messages, capture screenshots, activate the microphone, steal browser-held Telegram and WhatsApp data, and download additional malware.

Iranian Ministry of Intelligence and Security (MOIS)

The FBI calls it HEAVYGRAM, and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK. The malware is controlled via Telegram and can copy emails and chat messages, take screenshots, activate the microphone, steal credentials, download additional malware, and in at least one version wipe the computer.

MITRE ATT&CK

HEAVYGRAM in ATT&CK

35 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.