The FBI has released a major technical update on Iranian government-linked cyber activity targeting dissidents, journalists, opposition groups, and other individuals viewed as threats by Tehran, adding detailed forensic analysis of a malware family identified as HEAVYGRAM.
The new FLASH expands the technical picture surrounding Iranian Ministry of Intelligence and Security cyber operations already covered by TRJ. Our earlier reporting examined CHOSEN BRICK, another Iran-linked spyware operation targeting many of the same types of victims. The FBI’s latest document does not identify HEAVYGRAM as CHOSEN BRICK. Instead, it presents HEAVYGRAM as a separate malware analysis tied to the same broader MOIS threat environment and provides substantially deeper technical detail about how Iranian cyber actors establish access, maintain persistence, collect intelligence, and move stolen data from infected systems.
According to the FBI, Iranian cyber actors are using HEAVYGRAM on behalf of Iran’s Ministry of Intelligence and Security, or MOIS, to target Iranian dissidents, journalists critical of the Iranian government, opposition organizations, and other individuals perceived by Tehran as threats. The FBI assesses that the malware is likely being used to collect intelligence, support data leaks, and inflict reputational harm against targeted individuals.
The activity has been observed since at least the fall of 2023.
The FBI analyzed seven malware samples obtained through investigations and identified several stages of activity, including first-stage applications designed to masquerade as legitimate software, persistent second-stage implants, and related malware containing additional functions.
The infection process often begins through social engineering rather than through an immediate technical exploit.
Iranian actors have used Telegram, WhatsApp, and Instagram to approach potential victims while posing as people offering technical or IT assistance. Victims who accept the offer may be instructed to install the legitimate AnyDesk remote-access program and provide access information to the actor.
In other cases, targets are persuaded to download software that appears legitimate but actually launches a malware infection chain.
One of the first-stage samples identified by the FBI was Pictory_premium_ver9.0.4.exe, which masqueraded as a premium version of the Pictory AI video-generation platform.
The program presented the victim with a convincing graphical interface while malicious components were created behind the scenes. The FBI documented a VirusTotal-observed Vultr-hosted download location for the sample and published hashes associated with the executable so defenders can identify the malicious file.
Another sample, Telegram_Authenticator.exe, impersonated a Telegram authentication application.
When executed, the fake application displayed an activation-code prompt that appeared to belong to Telegram while writing additional files and Python components to the victim’s computer.
The FBI also found evidence that components of the malware attempted to weaken Microsoft Defender protections.
Malicious PowerShell commands created antivirus exclusions for directories used by the malware, including locations under ProgramData and the victim’s Telegram download directory.
Those exclusions could reduce the chances that malicious components stored in those locations would be detected during normal antivirus scanning.
The second-stage implants provide a much broader surveillance capability.
One persistent implant identified as winappx.exe contained functions capable of collecting system information, enumerating processes, identifying files and storage drives, extracting browser data, accessing Telegram content, targeting WhatsApp information, stealing Chrome credentials, retrieving email, taking screenshots, downloading additional files, and executing commands received from the malware’s operators.
The FBI analysis shows that browser information was a major target.
HEAVYGRAM-related components could collect data from Google Chrome, Microsoft Edge, and Mozilla Firefox, along with inventories of installed software and available drives.
One command identified by investigators, GetChromePass, was capable of extracting and decrypting Chrome credentials, writing them to a local file, and sending the stolen information back through the command-and-control infrastructure.
The malware also targeted email accounts.
The FBI identified functionality capable of accessing Microsoft Outlook mailboxes and extracting content from Inbox, Sent Items, Deleted Items, Archive, and Junk Email folders.
Messages and attachments could be written to disk, compressed, and prepared for exfiltration.
A separate malware component identified as MsCache.exe was capable of acquiring Gmail OAuth authentication tokens and associated email addresses.
The FBI found that stolen credentials and authentication material could then be transmitted to the attackers through Telegram-based command-and-control channels.
That distinction is important because OAuth tokens can provide access to an account without requiring an attacker to repeatedly enter the victim’s password.
HEAVYGRAM also contains functionality aimed at communications applications.
The FBI identified commands capable of collecting Telegram installation data, WhatsApp browser storage, application session material, and locally stored communications information.
Some functions could terminate the legitimate WhatsApp process and launch a separate executable from a malware-controlled location.
Microphone access was built into the operation as well.
The FBI documented an EnableMic capability that could download an additional microphone component, install it under the Windows ProgramData directory, establish persistence through the Windows registry, and execute the surveillance tool.
The malware’s command-and-control architecture relies heavily on legitimate online infrastructure.
Telegram’s API was used to transmit messages, screenshots, files, system information, and stolen data between infected machines and the operators.
The malware could also receive commands through Telegram, execute those instructions, and return the results to the attacker.
The FBI also identified use of Vultr object storage.
Custom code found inside the malware was capable of creating storage buckets, uploading stolen files, downloading additional components, listing stored objects, and deleting data.
That gave the operators another mechanism for moving information and malware components outside the infected machine.
HEAVYGRAM’s capabilities show that the malware is designed for more than a quick credential theft operation.
An infected system can potentially expose browser credentials, email, messaging sessions, screenshots, files, software inventories, attached storage, system information, and other sensitive material while allowing the attacker to maintain remote command capability.
For journalists, dissidents, activists, and opposition figures, the intelligence value of that access can be substantial.
A compromised computer may contain private communications, source material, contact lists, research, organizational documents, travel information, login credentials, correspondence with other activists, and records identifying additional people inside a targeted network.
The FBI’s analysis shows why social engineering remains central to these operations.
The threat actors do not need to defeat every security control directly if they can convince a victim to install the software themselves.
An offer of technical assistance can lead to AnyDesk access.
A fake installer can trigger the infection.
A convincing Telegram authentication application can persuade the victim to execute malware that appears legitimate.
Once access is established, HEAVYGRAM provides the operators with a much broader surveillance platform.
The FBI’s September update also expands the indicators of compromise available to defenders.
The FLASH contains hashes, executable names, directories, registry locations, command-and-control behavior, cloud-storage infrastructure, and other technical artifacts that can be used to identify HEAVYGRAM activity inside Windows environments.
The FBI recommends that users remain cautious when receiving unexpected communications from unknown people or unusual messages from people they already know.
Devices should be kept updated, software should be downloaded only from trusted vendor websites or official application stores, antivirus and anti-malware protections should remain enabled, strong and unique passwords should be used, and multifactor authentication should be activated wherever possible.
Suspicious messages should be reported, and suspected criminal activity can be reported to the FBI.
This latest FLASH significantly expands what defenders know about the technical side of Iranian intelligence-linked malware operations.
TRJ’s earlier CHOSEN BRICK coverage documented another spyware operation targeting dissidents, activists, and journalists connected to the same broader Iranian threat environment.
The HEAVYGRAM report adds a separate FBI malware designation and a far more detailed look at the tools, infection methods, persistence mechanisms, command-and-control channels, browser theft, email collection, messaging-app surveillance, cloud storage, and technical indicators now associated with MOIS-linked activity.
The distinction matters.
HEAVYGRAM should not simply be renamed CHOSEN BRICK without evidence establishing that they are the same malware family.
What the new FBI analysis does establish is that Iranian intelligence-linked cyber operations continue to rely on a combination of social engineering, trusted communications platforms, legitimate remote-access tools, fake software, persistent malware, and extensive data collection against people the Iranian government considers threats.
The technical picture is becoming clearer.
The objective remains the same: gain access to the target, remain inside the system, collect as much useful intelligence as possible, and quietly move that information back to the operators controlling the campaign.
Federal Bureau of Investigation (FBI) — Update on Government of Iran Cyber Actors’ Deployment of Telegram C2 to Push Malware to Identified Targets, FBI FLASH, September 15, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



