The UK NCSC, FBI and AIVD say Iran’s Ministry of Intelligence and Security (MOIS) is behind CHOSEN BRICK, a Windows spyware campaign they have tracked since at least 2025 against dissidents, activists and journalists in the UK, US and the Netherlands. The joint advisory adds fresh technical detail to an earlier FBI analysis and says the malware has only been seen on Windows systems.
The operation starts with a message in WhatsApp or Telegram from someone the target is led to trust, then a file that looks like a legitimate app. Once opened, CHOSEN BRICK can pull contacts, emails, chats, screenshots and microphone audio, and it uses Telegram itself for command and control, so both the lure and the traffic blend into normal messaging use.
That matters most for people whose work depends on the same apps for outreach and source contact: the trust layer is part of the attack path, not just the payload. The reporting also ties the campaign to transnational repression, since the stolen data can help map routines and relationships beyond the device itself.