The intelligence services of Iran are employing a Windows-based malware family, dubbed Chosen Brick, to surveil and harass dissidents, journalists, and activists globally, according to a joint advisory issued by the UK’s National Cyber Security Centre (NCSC), the U.S. Federal Bureau of Investigation (FBI), and the Netherlands’ AIVD. This malware has been active since at least 2025, enabling Iranian state-sponsored cyber actors to gather sensitive information, including contacts, emails, and social media messages, which could facilitate tracking of victims’ movements.
The advisory highlights that the risks for victims extend beyond cyber intrusion. Personal information obtained through Chosen Brick has reportedly appeared on pro-Iranian leak sites, potentially exposing individuals to further harassment, intimidation, or physical threats. The agencies noted that Iranian intelligence services have previously been linked to plots involving kidnapping or lethal operations against perceived opponents abroad.
The attack methodology typically begins with social engineering via messaging applications like WhatsApp or Telegram. Iranian cyber actors engage with targets, sometimes for extended periods, to build rapport and trust. This social engineering is highly tailored, leveraging detailed information gathered through prior reconnaissance. Attackers may impersonate individuals known to the target or pose as technical support staff from the messaging platform to enhance credibility.
After establishing trust, the attackers attempt to deliver the malware through lure files disguised as legitimate software installers or documents. Examples include fake installers for applications such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, or KeePass. In some instances, the lure files have been disguised as MRI scan results. Upon opening, these files display a convincing decoy screen while the Chosen Brick payload installs silently in the background, granting attackers control over the compromised Windows device.
Chosen Brick establishes persistence on infected systems by creating a registry Run key, ensuring it survives system reboots. It also attempts to add exclusions to Microsoft Defender to evade detection. The malware has exclusively been observed targeting Windows systems.
The attackers often initially target a victim's work device. However, if this attempt fails or if they suspect detection, they may pivot to targeting personal devices, asking victims to open the malicious file on their personal phones or computers, thereby bypassing corporate security controls. This strategy underscores the challenge for organizations in securing personal devices used by employees, which typically fall outside the scope of corporate IT oversight.
This is not the first instance of Iranian state-linked actors using Telegram-based malware against the Iranian diaspora. In March, the FBI reported similar activity dating back to late 2023, where Iranian actors utilized Telegram as command infrastructure to target dissidents. The recent joint advisory provides a formal name, joint attribution, and a more detailed operational overview of the malware, consolidating information that security researchers had previously tracked under various names.






