Skip to content

Security1 publisher3 min readPublished

Iran's HEAVYGRAM spyware assigns each infected Windows PC its own Telegram bot

The September 15 advisory from the NCSC, the FBI and the AIVD lists a registry Run key, a folder path with a stray space and traffic to api.telegram.org as the practical detection points for at-risk staff.

The Watch · Security desk

Photograph accompanying Iran's HEAVYGRAM spyware assigns each infected Windows PC its own Telegram bot
Photo: fbi.gov

What happened

  • The U.K. NCSC, the FBI and the Dutch AIVD published a joint advisory on September 15 describing Windows spyware the agencies say Iran's intelligence service uses against dissidents, journalists and activists.
  • The second stage gives each infected computer its own Telegram bot, which the agencies say keeps one victim's activity from mixing with another's.
  • Published indicators include Run key entries named SMQDService or winappx, a folder path with an added space at C:\Windows \SysWOW64, and unexpected connections to api.telegram.org.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Alerting on api.telegram.org means writing rules that survive normal Telegram use in the office, so the work lands on host telemetry for a small named group of people.
  • exposure The work-to-personal pivot puts the eventual compromise on a device outside employer monitoring. That is where an at-risk employee's contacts and routine actually get taken.
  • capability Per-victim bots give the operators isolation and spare them the cost of buying or defending hosting, and they push the burden of disruption onto Telegram's abuse process one account at a time.
  • constraint For anyone supporting dissidents or exiled journalists, response to one of these infections has to cover physical safety alongside credential resets and reimaging.

One Telegram bot per infected machine decides what defenders can do about the channel [11]. Getting a single bot killed cuts one victim's control path and leaves every other victim's in place. The traffic goes to api.telegram.org, the endpoint every legitimate Telegram client on the network also uses, and newer builds route it through proxy servers to hide it [16][15].

The advisories list a Run key entry named SMQDService or winappx, and a folder path with an added space, C:\Windows \SysWOW64, where the malware drops extra files [16]. The same sample tells Microsoft Defender to skip certain folders so its files are not scanned [10].

The operator poses as someone the target knows, or as tech support for a messaging app, builds trust, then sends a file that looks like a legitimate program [6]. Observed disguises include the AI video app Pictory, the password manager KeePass, Telegram itself, RunwayML, Norton Antivirus and Adobe Flash Player; in some cases the file was dressed up as MRI scan results [7]. Opening it puts a convincing fake app screen on the display while the first stage installs, and the second stage registers the machine with its bot [8].

Attackers often begin on a target's work computer, the agencies say, and when that fails they try to move to a personal device [17]. That personal device sits outside company security. For an employer with journalists or activists on the payroll, the compromise ends up on hardware outside the security team's telemetry.

Nothing here worms. The agencies say the malware has not been seen spreading across a network on its own, though it can download more tools [13], and every version seen so far runs only on Windows [9]. So one infection is one person: running programs enumerated, screenshots, microphone recording, Telegram and WhatsApp data copied out of the browser, saved passwords and email addresses stolen, files deleted, and in at least one version the computer wiped [12]. Stolen files leave through the bot and through cloud storage such as Vultr and Storj [14].

The FBI attributes the malware to Iran's Ministry of Intelligence and Security and dates the wider campaign to the autumn of 2023 [3]. The advisory says CHOSEN BRICK has been used against people in the U.K., the U.S., the Netherlands and elsewhere since at least 2025 [4]. The FBI's March 2026 alert was the first public description of the campaign, and the September 15 release adds technical detail and new indicators of compromise [5]: about six months on from the first alert [2], roughly three years after the campaign began [1].

Collection here feeds targeting. Screenshots and other collected data show a target's contacts, location and daily routine, and the personal details of some victims have appeared on pro-Iranian leak sites, which the advisory says can increase the risk to their safety [19]. In March the U.S. Justice Department seized four such sites, which it said had been used to post stolen data and to call for the killing of dissidents, journalists and others [20]. The agencies say Iran's intelligence services have in some cases plotted to kidnap or kill such people abroad [21].

What to watch

  • Whether a non-Windows build turns up; every version the agencies have seen runs only on Windows.
  • Whether proxy fronting spreads to all builds. That would strip api.telegram.org of its value as a network indicator.
  • Whether Telegram acts on the per-victim bot accounts, and whether the operators then move the control channel to another platform.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories