Threats · 27m ago
The UK NCSC, FBI and AIVD say Iran’s Ministry of Intelligence and Security (MOIS) is behind CHOSEN BRICK, a Windows spyware campaign they have tracked since at least 2025 against dissidents, activists and journalists in the UK, US and the Netherlands. The joint advisory adds fresh technical detail to an earlier FBI analysis and says the malware has only been seen on Windows systems.
The operation starts with a message in WhatsApp or Telegram from someone the target is led to trust, then a file that looks like a legitimate app. Once opened, CHOSEN BRICK can pull contacts, emails, chats, screenshots and microphone audio, and it uses Telegram itself for command and control, so both the lure and the traffic blend into normal messaging use.
That matters most for people whose work depends on the same apps for outreach and source contact: the trust layer is part of the attack path, not just the payload. The reporting also ties the campaign to transnational repression, since the stolen data can help map routines and relationships beyond the device itself.
3 sources covering this story
Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
U.S., U.K., and Dutch agencies say Iran’s intelligence service uses Telegram-controlled Windows malware to spy on dissidents and journalists.
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Iranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
Part of the PlainSec briefing for 2026-09-15