Iranian State Actors Deploy CHOSEN BRICK Malware to Target Dissidents Globally
UK's NCSC, alongside US and Dutch intelligence agencies, warns of CHOSEN BRICK malware used by Iran to spy on dissidents, activists, and journalists worldwide.

The UK's National Cyber Security Centre (NCSC), in collaboration with the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service (AIVD), has issued a joint advisory detailing the activities of Iranian state-sponsored cyber actors utilizing a malware family known as CHOSEN BRICK. This sophisticated malware has been actively deployed since at least 2025, targeting individuals across the UK, US, and the Netherlands, with the primary objective of gathering sensitive information that could facilitate the tracking of dissidents, activists, and journalists.
The advisory highlights that Iran almost certainly employs cyber operations as a tool to suppress perceived threats to its regime. This includes not only digital espionage but also, in some documented instances, plots for international kidnapping or lethal operations against individuals deemed enemies of the state. The personal data exfiltrated by CHOSEN BRICK has, in some cases, been published on pro-Iranian leak sites, thereby amplifying the personal safety risks for victims.
Iranian cyber actors employ a highly tailored approach to their targets, often leveraging extensive prior research to craft convincing social engineering campaigns. These attacks typically commence via social messaging platforms like WhatsApp and Telegram, where actors impersonate trusted entities or even technical support personnel to build rapport. The malicious payload is then disguised as an authentic file, often mimicking legitimate applications such as Pictory, RunwayML, or even security software like Norton Antivirus, or seemingly innocuous documents like MRI scan results.
Initial infection attempts often target work-related or corporate devices. If these efforts are unsuccessful or deemed too risky, the actors may pivot to requesting the target open the file on their personal devices, thereby circumventing corporate security controls. Regardless of the file's thematic disguise, the underlying malicious component, CHOSEN BRICK, is deployed in the background, establishing control over the victim's Windows operating system.
Once installed, CHOSEN BRICK establishes persistence by creating registry keys, ensuring it survives system reboots. It also attempts to evade detection by adding exclusions to Microsoft Defender antivirus. Command and control (C2) communication is managed through Telegram, with each victim device connecting to a unique Telegram Bot ID to maintain operational security and prevent cross-contamination. While the malware has not been observed to exhibit automated lateral movement capabilities, it can download and execute additional malware, technically enabling such actions.
The CHOSEN BRICK malware possesses a broad range of functionalities, enabling it to perform various objectives. These include enumerating running processes and system information, capturing screenshots, recording audio via the microphone, stealing data from Telegram and WhatsApp, downloading or deleting files, exfiltrating email content, and even wiping the entire computer system. Screen capture is a frequently observed feature, providing actors with insights into the victim's contacts, location, and daily routines.
The advisory provides comprehensive technical details on the attack chain, delivery and exploitation methods, installation persistence, and actions on objectives. It also offers crucial mitigation strategies for individuals and organizations to enhance their defenses against these persistent threats. The joint nature of this advisory underscores the global reach and coordinated efforts to counter these Iranian cyber operations.
This advisory from the NCSC, US FBI, and Dutch AIVD provides specific technical details on the CHOSEN BRICK malware, including its persistence capabilities and its exclusive targeting of the Windows operating system. It also highlights the social engineering tactics used, such as impersonating contacts on messaging apps and using lures like fake medical results, to trick victims into downloading the spyware. The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of individuals perceived as threats to the regime.