Security1 publisher2 min readPublished
UK, US and Dutch agencies name CHOSEN BRICK as Iranian spyware aimed at dissidents
The joint advisory describes a Windows implant that arrives over WhatsApp or Telegram once the operator has earned a target's trust, harvests inboxes, screen and microphone, and runs a separate Telegram bot for each victim.
The Watch · Security desk
What happened
- Britain's NCSC, the FBI and the Dutch AIVD issued a joint advisory on Tuesday naming CHOSEN BRICK, spyware used by Iranian state-sponsored operators, with victims in all three countries since at least 2025.
- Operators open contact on WhatsApp or Telegram posing as a known contact or technical support, build rapport, then send a file matched to the pretext, in one case a fake MRI scan of a disk herniation.
- The Windows-only implant collects contacts, email inboxes and social media messages, captures what is on screen, and can switch on the device's microphone.
- Command and control runs through Telegram with a separate bot assigned to each victim, and the agencies say the most recent versions route their traffic through proxies.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The people in scope are staff whose home Windows machines the employer does not manage, and the NCSC's advice is to warn them and help them check those devices.
- constraint Blocking one bot protects one person, so triage cost tracks the number of at-risk staff.
- capability Remote microphone and screen capture give an intelligence service a file on one person's movements and conversations. For an employer, that is safety casework.
- contradiction The FBI attributes matching tradecraft to actors working on behalf of MOIS while the joint advisory stops at Iranian state-sponsored, so an organisation briefing staff has to pick which attribution it repeats.
The durable artefacts are on the host. The implant relaunches at login so it survives a reboot [8], and it writes exclusions into Microsoft Defender to cut its chance of being caught [9]. Stolen files leave over Telegram and commercial cloud storage services [11], traffic most networks already permit. An unexplained Defender exclusion on a journalist's personal Windows laptop is the cheapest item on that list to check.
The decoy file matches whatever story the operator has told. Alongside the fake MRI scan, the operators have impersonated Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass [18]. Two of the six are security products, Norton Antivirus and KeePass [1].
The file arrives late in the conversation. Operators tailor the approach to each target, and the agencies say that produces wide variation in how a compromise begins [6]. The advisory describes the social engineering as extensive and does not say how long the rapport-building takes.
The NCSC did not identify a specific Iranian government entity behind the campaign [20]. In March the FBI did, in a flash warning that blamed actors operating "on behalf of the Government of Iran Ministry of Intelligence and Security", and the tradecraft in the new advisory closely matches that activity [21]. The bureau said similar Telegram-based malware has targeted Iranian dissidents and journalists since fall 2023 [22], about 15 months before the earliest victims the joint advisory covers [2]. It linked a July 2025 hack-and-leak operation to "Handala Hack", a persona it assesses is operated by MOIS and connected to a group called "Homeland Justice" [23]. Also in March, the State Department reissued a $10 million reward for information on hackers connected to Iranian cyber actors after the compromise of FBI director Kash Patel's personal email account [24], and the bureau seized several leak sites tied to MOIS that had hosted stolen material [25].
Iran has used this and similar cyber activity to "support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists", according to the NCSC [16]. The agencies say the harvested data builds a pattern of life, a map of a victim's location, contacts and daily routine [14]. Personal details taken this way have surfaced on pro-Iranian leak sites and been used to harass victims further [15]. The NCSC also said Iranian intelligence services have plotted to kidnap and assassinate individuals seen as enemies of the regime, including internationally [17].
What to watch
- Whether the NCSC follows the advisory with published hashes or Telegram bot identifiers to go with the behavioural description.
- Whether any of the three agencies puts a duration on the rapport-building phase or releases sample chat pretexts.
- Whether non-Windows builds surface and widen the pool of reachable personal devices.