The UK's National Cyber Security Centre, the FBI and the Netherlands' AIVD issued a joint advisory naming CHOSEN BRICK, a spyware tool used by Iranian state-sponsored operators against individuals the regime treats as threats. The NCSC's framing is unusually direct: Iran has used this and similar activity to "support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists", and in some cases Iranian intelligence services have plotted to kidnap and assassinate individuals internationally, including people perceived as enemies of the regime. The tool harvests contacts, email inboxes and social-media messages, captures screen content and can switch on the device microphone; the agencies state that the resulting collection supports a pattern of life โ a map of the victim's location, contacts and daily routine โ which increases the physical risk to the person involved. Stolen personal details have surfaced on pro-Iranian leak sites to compound the harassment. The attack chain is rapport-led and highly tailored: initial contact comes over WhatsApp or Telegram, often impersonating a known contact or technical support, with operators building a relationship before delivering a file disguised to match the pretext. Lures have impersonated Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, and the advisory illustrates the tailoring with a fabricated MRI scan showing a disc herniation. CHOSEN BRICK is Windows-only, relaunches at login to survive reboot, and adds exclusions to Microsoft Defender to reduce detection; it uses a separate Telegram bot per victim for command and control, which limits the blast radius if one device is discovered, and sends exfiltrated files through Telegram alongside commercial cloud storage, with the most recent versions using proxies to conceal traffic. The advisory covers victims in all three countries dating back to at least 2025. The NCSC did not attribute the campaign to a specific Iranian entity, but notes the tradecraft closely matches an FBI flash warning circulated in March 2026 that attributed similar Telegram-based malware activity to actors operating on behalf of the Government of Iran Ministry of Intelligence and Security, and linked a July 2025 hack-and-leak to a persona the bureau assesses is also MOIS-operated. The agencies warn that attackers may try to move targets onto personal devices to bypass workplace security, and urge organisations with at-risk staff to circulate the warning and help employees check their own phones and computers โ a recognition that the workplace perimeter is not the boundary of the risk.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-16 |
| Source | The Record |
| Reliability | Tier 2 |