Trust, Then Malware: Inside Iran's Spyware Playbook

Sep 17, 2026 | Spyware

John Davies

Malloc

Illustration representing spyware and state surveillance of mobile devices

Iran's hackers keep getting caught. They also keep coming back — with new tricks, new targets, and the same old playbook.

In September 2026, three Western spy agencies published a joint warning about a piece of malware they had been tracking for years. The British called it CHOSEN BRICK. The FBI called it HEAVYGRAM. Both names refer to the same tool: a Windows implant that Iranian intelligence has been using to break into the computers of people the regime considers enemies.

The targets are predictable. Dissidents. Activists. Journalists. People who fled Iran and thought distance would keep them safe.

The methods are not. And that is what makes this story worth telling.

First, a trip back to 2021

Five years before CHOSEN BRICK made headlines, researchers at Check Point pulled back the curtain on a different Iranian operation. They called it Domestic Kitten. The weapon was an Android spyware family with a deceptively cute name: FurBall.

FurBall did not exploit some exotic software vulnerability. It did not need to. It simply asked people to install it.

The attackers built fake apps — a Tehran restaurant ordering service, a wallpaper app, a news reader, a translation tool. Some were repackaged versions of real games pulled straight from Google Play. They spread them through Iranian blogs, Telegram channels, and SMS messages. Once someone tapped “install,” the trap closed.

What happened next was quiet and methodical. FurBall registered itself to restart every time the phone rebooted. It began uploading photos, videos, and call recordings every twenty seconds. It logged SMS messages, tracked location, recorded ambient audio through the microphone, and catalogued every app on the device.

By the time Check Point published its findings, roughly 1,200 people had been targeted. More than 600 devices were confirmed infected across seven countries — Iran, the US, the UK, Pakistan, Afghanistan, Turkey, and Uzbekistan.

The servers receiving all this data were sitting in Tehran and Karaj.

The mobile campaign that kept evolving

FurBall did not disappear after the exposure. It adapted.

ESET researchers picked up a new variant in 2022, distributed as a translation app through a copycat of a legitimate Iranian website. The fake site mimicked downloadmaghaleh.com, a service that provides Persian translations of English articles and books. A button labelled “Download the application” in Persian carried the Google Play logo — but clicking it did not take users to Google Play. It downloaded the APK directly from the attackers' server.

This version was technically stripped down. It requested only one intrusive permission: access to contacts. The researchers suspected this was deliberate — a way to stay under the radar while the attackers prepared for a more aggressive phase, perhaps a spear-phishing campaign via text messages. If they later expanded the app's permissions, FurBall would be capable of exfiltrating far more: clipboard contents, SMS messages, device location, call logs, recorded phone calls, notification texts, device accounts, file lists, running apps, and the full list of installed applications. It could even receive commands to take photos and record video, uploading the results directly to its command-and-control server.

The code underneath had been lightly obfuscated — class names, method names, strings, and server URIs scrambled to frustrate detection. The command-and-control server needed only minor adjustments, mostly renaming the PHP scripts it used. The core surveillance framework, built on the open-source parental-control tool KidLogger, remained unchanged.

That is the thing about FurBall. It was never technically brilliant. It was just persistent.

Fast forward to 2026

CHOSEN BRICK is a different animal. It does not run on phones at all. It is Windows-only.

But the way it gets onto a victim's machine will feel familiar to anyone who has followed Iranian cyber operations. It starts with a conversation.

The operators do their homework first. They research a target — their job, their interests, their social circle. Then they reach out on WhatsApp or Telegram, pretending to be someone the target knows or someone from platform support. They chat. They build trust. Days pass.

Then they send a file.

The file is tailored to whatever pretext the conversation has established. Sometimes it is a fake installer for a legitimate program — Pictory, RunwayML, Norton Antivirus, KeePass, Telegram, Adobe Flash Player. Sometimes it is something more personal. The agencies specifically mentioned a fake MRI scan showing a herniated disc, sent to someone who had been told they needed medical results.

When the target opens it, they see what they expect to see — a real-looking application window, or a medical document. In the background, the real payload installs itself.

There is one detail in the advisory worth pausing on. The attackers often try the target's work computer first. If corporate security blocks the file, they do not give up. They ask the target to open it on their personal laptop instead.

That is not a technical trick. That is a psychological one. And it works.

How the malware stays hidden

Once CHOSEN BRICK is running, it does not do anything fancy. It writes a single entry to the Windows registry — a user-level key that tells the system to launch the malware every time the user logs in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Observed value names include SMQDService and winappx, pointing to executables placed under paths like C:\ProgramData\SMQDServicePackages\. Because it sits under HKCU, no administrator privileges are required. No exploit needed.

It also adds itself to Microsoft Defender's exclusion list, so antivirus scans skip right over it.

The command-and-control setup is where things get interesting. Instead of using traditional servers, the malware communicates through Telegram. Each infected device gets its own unique Telegram bot. That means if one victim's implant is discovered, the others stay hidden. It is a simple design choice with a big operational payoff.

Recent versions route their traffic through commercial proxies to make the communications harder to trace.

From there, the operators can do almost anything. They can watch the screen. They can turn on the microphone. They can pull emails, Telegram messages, WhatsApp chats. They can download more malware. They can delete files — or wipe the device entirely.

Notably, there are no zero-day exploits in this chain. The whole operation depends on one thing: getting a human being to trust the wrong person.

The bigger picture

Mobile spyware did not disappear when Iran moved to Windows. It remains the most technically sophisticated corner of the state-surveillance arsenal — and several families deserve their own analysis.

  • Predator (Cytrox/Intellexa) repurposes ARM's NEON vector registers as a covert kernel-to-user data channel, and bypasses Apple's Pointer Authentication Codes by locating a 20-byte gadget sequence inside Apple's own JavaScriptCore framework — using Apple's code as a signing oracle rather than implementing its own cryptography.
  • Pegasus (NSO Group) remains the zero-click benchmark. FORCEDENTRY hid a malicious PDF inside a GIF delivered via iMessage; iOS rendered the preview automatically, and the message was deleted before the target ever saw it.
  • QuaDream exploited an iOS 14 quirk in which backdated iCloud calendar invites were added silently. Its KingsPawn implant could record calls, capture camera images, and hijack Apple's Anisette framework to mint iCloud one-time passwords — persistent access without persistent device compromise.
  • Graphite (Paragon Solutions) targets messaging apps rather than the full device, reading WhatsApp, Signal, Telegram, and LINE content after on-device decryption. A February 2026 OPSEC failure — a LinkedIn photo showing the control dashboard — exposed targeted numbers across Europe.
  • NoviSpy (Serbia) represents a different model entirely: physical access. Amnesty International found it on a student's Android device after police custody, apparently installed via a Cellebrite forensic tool.

What happens to the data

One detail from the joint advisory is easy to miss: stolen personal information from some CHOSEN BRICK victims has appeared on pro-Iranian leak sites.

Contact lists and messages are not just intelligence. Once published, they become a map — who knows whom, who talks to whom, who is worth targeting next.

The NCSC was explicit about the physical danger. Iranian intelligence has, in some cases, plotted kidnappings and assassinations abroad. In October 2025, MI5's Director-General said British services had tracked more than 20 potentially lethal Iran-backed plots in a single year.

The chain from surveillance to physical harm is short. Screenshots and microphone audio establish a pattern of life. Browser data exposes relationships. Email theft opens the social graph. Once weaponized — through leaks or as operational support — the surveillance has done its job.

The phone in your pocket is still the prize

There is a reason Iran's operators keep coming back to mobile — and a reason the CHOSEN BRICK shift to Windows is not a retreat but a workaround.

Phones hold the densest concentration of personal data most people own. Location history. Private messages. Microphone access. Camera. Contacts. Banking apps. Two-factor authentication codes. They are rarely left behind, rarely powered off, and almost always within arm's reach. For an intelligence service building a pattern of life, a compromised phone is worth more than almost any other single target.

That is what makes FurBall's persistence so instructive. It did not need a zero-day. It needed a boot receiver and a convincing icon. And even after public exposure and improved store defences, the same operators kept iterating — new lures, new obfuscation, same surveillance objective.

The 2026 pivot to Windows tells us something important: attackers go where defences are weakest. When mobile hardened, they moved sideways to desktops. But the mobile threat never went away. It is still there, still being refined, still aimed at the people least able to afford compromise.

For dissidents, journalists, activists, and diaspora communities, mobile security is not a technical nicety. It is the difference between a private life and a mapped one. Between staying out of reach and appearing on a leak site. In some documented cases, between safety and a plot against their life.

The agencies issuing these advisories are clear about what helps: keep devices updated, install apps only from official stores, treat unsolicited files and messages with suspicion, and use tools designed to detect compromise rather than merely prevent it.

Where Malloc fits

Malloc is built for that last recommendation: detecting compromise rather than claiming to prevent all of it. It runs its analysis on the device, alerts you when an app uses your camera or microphone, shows which domains the apps on your phone contact, and flags permissions that apps misuse. It detects and reduces risk; it does not make a phone unbreakable. More on protecting high-risk individuals, and the wider mobile security picture.

The spyware keeps adapting. The defence has to adapt faster — and it has to live on the device that matters most.

Relevant tags:

#Spyware#Iran#Mobile Security#Android#State Surveillance#Malloc

Published on Medium

Related articles