AKSK has published a technical analysis of HEAVYGRAM, also known as CHOSEN BRICK, which has been used in cyber-espionage campaigns targeting activists and journalists in various countries. According to the analysis, these activities are linked to cyber threat actors operating on behalf of Iran’s Ministry of Intelligence and Security (MOIS).
The document examines the malicious file, its execution and persistence mechanisms, its communication with command-and-control (C2) infrastructure, its malicious functionality, and the associated indicators of compromise. The analysis also provides specific recommendations for identifying, monitoring, and responding to potential compromises.
Read the full analysis: https://aksk.gov.al/en/technical-analysis-of-the-malicious-file-nanocore/
