Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
NCSC, FBI, and AIVD warn Iranian state-linked actors deliver CHOSEN BRICK Windows spyware via fake AI apps, antivirus installers, and MRI-result lures.
A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK (FBI tracking name: HEAVYGRAM), Iranian state-linked Windows spyware targeting dissidents, activists, and journalists worldwide since at least 2025. Lures impersonate Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, and operators pivot conversations from corporate to personal devices to bypass enterprise controls. The spyware persists via Registry Run keys, adds Microsoft Defender exclusions, uses per-victim Telegram bots for command-and-control, and exfiltrates screenshots, audio, email, and chat data via Telegram and cloud services, with some victim data appearing on pro-Iranian leak sites.
- Lures impersonate Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass
- Persistence via HKCU Run key; malware adds Microsoft Defender exclusions
- Per-victim Telegram Bot IDs; HTTPS and SOCKS5 proxies conceal C2 traffic
- Capabilities include screenshots, audio capture, email/chat theft, downloads, and data wiping
- Operators move targets from corporate devices to personal systems to evade EDR
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | api.telegram.org | orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[. |
| domain | backblazeb2.com | uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an |
| domain | iproyal.com | backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn |
| domain | lightningproxies.net | , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n |
| domain | storjshare.io | .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly |
| domain | vultrobjects.com | pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.] |
Full article778 words · extracted from gbhackers.com · click to collapse
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists.
A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted individuals worldwide, including in the UK, US and Netherlands, since at least 2025.
The malware is notable not only for its surveillance capabilities, but also for the operational context in which it is deployed.
Authorities assess that Iranian cyber activity is being used to support repression of people perceived as threats to the regime.
In certain cases, Iranian intelligence services have allegedly pursued kidnappings or lethal operations against overseas targets, making the compromise of personal devices a potentially serious physical-safety issue rather than merely a data-security incident.
They may impersonate a contact known to the victim, or pose as technical support staff from a messaging service.
The social-engineering pretext is tailored using detailed target research, allowing the delivered file to appear relevant and credible.
Observed lures have impersonated legitimate software such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass.
In other cases, operators sent files that appeared to contain MRI scan results, including a lure referencing a disk herniation.
The attackers frequently contact a target through a work or corporate device first. If corporate controls prevent execution, or the risk of detection is too high, they attempt to move the conversation to the victim’s personal system.
This shift is designed to bypass enterprise endpoint protection, application-control policies and centralized monitoring.
When opened, the malicious file presents a convincing decoy screen matching its theme.
Behind that interface, it downloads and executes the core CHOSEN BRICK component. All known cases have targeted Windows systems exclusively.
NCSC Researchers said in a report shared with GBhackers, the operators begin by building trust through social messaging platforms, including WhatsApp and Telegram.
CHOSEN BRICK Malware
CHOSEN BRICK establishes persistence through the Windows Registry Run key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
This mechanism enables the malware to launch when the compromised user logs in, without requiring administrative privileges.
The malware also attempts to add Microsoft Defender exclusions, reducing the likelihood that its files will be scanned or removed.

For command-and-control, CHOSEN BRICK communicates with Telegram.
Each victim reportedly receives a distinct Telegram Bot ID, an operational-security measure that limits overlap between compromised hosts and complicates attribution or bulk detection.
Recent samples have also used HTTPS and SOCKS5 proxies to conceal Telegram-related traffic.
The spyware can download additional payloads and establish persistence for them.
Although investigators have not observed automated lateral movement, the modular download capability gives operators the flexibility to expand activity beyond the initial implant.
CHOSEN BRICK supports extensive collection and destructive actions.
Operators can enumerate processes and system information, capture screenshots, record audio through the microphone, steal email content, collect Telegram and WhatsApp data from browsers, download files and delete or wipe data.
Screenshots are particularly valuable for intelligence collection because they can reveal contacts, conversations, schedules, locations and patterns of life.
The advisory notes that personal information from some prior victims has appeared on pro-Iranian leak sites, potentially increasing harassment and personal-safety risks.
Stolen data may be exfiltrated through Telegram bots or cloud storage services, including VultrObjects and StorjShare.
Defenders should investigate unexpected access to api[.]telegram[.]org, backblazeb2[.]com, vultrobjects[.]com, storjshare[.]io, iproyal[.]com and lightningproxies[.]net, particularly where such connections do not align with normal business use.
Organizations supporting high-risk personnel should extend detection and response beyond managed corporate endpoints.
The campaign’s deliberate pivot to personal devices means security teams should provide targeted awareness guidance and assistance to staff, journalists, activists and other individuals likely to be targeted.
Administrators should hunt for suspicious Registry Run-key entries, unexpected Defender exclusions, Telegram-linked communications and anomalous executables stored in unusual directories.
One observed payload location was C:\Windows \SysWOW64, where the deliberate space after “Windows” creates a nonstandard directory path intended to blend into legitimate Windows file-system activity.
Users should avoid installing software delivered through unsolicited attachments or messaging links, obtain applications only from official vendor sites or trusted app stores, keep Windows and security software updated, and treat SmartScreen warnings as a critical signal rather than an inconvenience.
The FBI tracks the same malware family as HEAVYGRAM, expanding the set of names defenders should include in threat-hunting and intelligence workflows.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/chosen-brick-malware/