LONDON — British, American, and Dutch security agencies have issued a joint warning about an Iranian state-linked spyware campaign targeting dissidents, activists, journalists, and other individuals perceived as threats to the Iranian government.
The malware family, tracked by the United Kingdom’s National Cyber Security Centre as CHOSEN BRICK, has been used against victims in the United Kingdom, United States, and the Netherlands since at least 2025. The FBI has traced related Iranian Ministry of Intelligence and Security cyber activity back to the fall of 2023.
The campaign relies heavily on personalized social engineering.
Attackers research individual targets, make contact through messaging platforms such as WhatsApp and Telegram, and work to establish trust before attempting to convince the victim to download and open a malicious file.
The person contacting the target may pose as someone already known to the victim or as technical support associated with a messaging platform.
The files are then tailored to fit the story being used against the individual.
Security agencies have observed malicious files disguised as legitimate applications and services including Pictory, RunwayML, Norton-branded antivirus software, Telegram, Adobe Flash Player, and KeePass.
In one of the more unusual lures identified by investigators, attackers sent a malicious file disguised as MRI scan results.
The strategy is designed to make the malicious file appear relevant and believable to the specific person being targeted.
Once opened, the file presents content consistent with the attacker’s story while CHOSEN BRICK installs in the background and gives the operators access to the Windows device.
The malware has been observed exclusively on Windows systems.
CHOSEN BRICK establishes persistence so it can remain active after the computer is restarted. One method involves creating entries under the Windows registry Run key, allowing the malware to relaunch when the user signs back into the system.
It can also add exclusions to Microsoft Defender in an effort to reduce the chance of detection.
Once installed, the spyware provides the operators with extensive surveillance capabilities.
CHOSEN BRICK can collect system information, enumerate running processes, capture screenshots, activate the computer’s microphone, steal email content, collect browser-based Telegram and WhatsApp information, download additional malicious files, and delete files.
At least one analyzed version also contained functionality capable of wiping the compromised computer.
The intelligence value of that access extends well beyond stealing individual files.
Screen captures, email records, messaging histories, contacts, audio, and device information can be combined to identify who a target communicates with, where that person may be located, what organizations they interact with, and how their daily routines develop.
British security officials warned that this information can be used to establish a detailed pattern of life around a targeted individual.
That creates a physical-security concern in addition to the digital compromise.
The NCSC assesses that Iran almost certainly uses cyber operations to support the repression of people viewed as threats to the government, including dissidents, activists, and journalists.
The agency also warned that Iranian intelligence services have been linked to international plots involving kidnapping or lethal operations against individuals perceived as enemies of the Iranian government.
Some information stolen from previous CHOSEN BRICK victims has appeared on pro-Iranian leak sites, exposing victims to further harassment and potentially increasing risks to their personal safety.
The FBI has separately attributed related malware activity to cyber actors operating on behalf of Iran’s Ministry of Intelligence and Security.
In a March 2026 cyber alert, the FBI said MOIS actors had used Telegram-based command-and-control infrastructure to distribute malware targeting Iranian dissidents, journalists opposed to the Iranian government, organizations with views contrary to official Iranian narratives, and other individuals considered threats by the government.
The FBI said those operations resulted in intelligence collection, data theft, leaks, and reputational harm against targeted individuals.
Telegram plays a central role in the CHOSEN BRICK infrastructure.
After compromising a system, the malware connects to Telegram for command and control.
Each infected device has been observed connecting to a separate Telegram Bot ID.
That separation reduces the chance that discovery of one victim’s infrastructure will immediately expose other compromised systems.
Stolen information can also be moved out of infected systems through Telegram and commercial cloud storage services.
Researchers identified the use of services including VultrObjects and StorjShare for data exfiltration.
Newer CHOSEN BRICK versions have also used HTTPS and SOCKS5 proxy infrastructure to make Telegram-related traffic more difficult to identify.
The attackers have also shown awareness of corporate security controls.
If an attempt to compromise a victim’s workplace device fails or appears too risky, the operators may encourage the target to open the malicious file on a personal computer instead.
That approach allows the attacker to bypass enterprise security systems that may exist on employer-managed devices.
The NCSC has urged organizations with employees at heightened risk to warn them about the campaign and help them examine personal devices in addition to corporate systems.
The Netherlands’ General Intelligence and Security Service said victims in the Netherlands have been informed and warned that Iranian cyber actors are using malware to access personal devices, email accounts, social media, contacts, routines, and location information.
The AIVD also advised potential targets to obtain software only from official websites or application stores, maintain current operating systems and applications, keep antivirus protection enabled, and avoid bypassing Microsoft SmartScreen warnings.
CHOSEN BRICK is not designed around broad, indiscriminate infection.
The operation depends on selecting individuals of interest, researching them, constructing a believable pretext, and convincing them to execute the malicious file themselves.
That makes awareness of social engineering as important as technical defenses.
A file does not become trustworthy because it appears to come from someone familiar, claims to contain medical information, carries the branding of legitimate software, or arrives through a messaging platform the victim uses every day.
Targets facing elevated risk should independently verify unusual requests through a separate communication channel before opening files or installing applications.
The NCSC has also published technical indicators defenders can search for when investigating suspected CHOSEN BRICK infections.
Observed persistence has included entries under the Windows registry path HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
Previously observed malicious value names have included SMQDService and winappx, though authorities caution that file names, directories, and registry values can change between campaigns and should not be treated as the only possible indicators.
The joint advisory from the NCSC, FBI, and AIVD demonstrates that the campaign is being treated as more than a conventional malware operation.
The central concern is the combination of cyber surveillance and real-world targeting.
A compromised computer can expose communications, associates, movement patterns, private conversations, identifying information, and other intelligence that may place the target and people around them at greater risk.
For dissidents, journalists, activists, and others targeted because of their work or political activity, the consequences of a successful infection can therefore extend far beyond loss of data.
CHOSEN BRICK gives its operators a window into the victim’s digital life.
When that information is collected by state-linked actors already focused on a specific individual, the infected computer can become a surveillance platform capable of mapping relationships, monitoring activity, stealing communications, and supporting further operations against the person behind the screen.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



