The UK National Cyber Security Centre, FBI, and Netherlands AIVD have disclosed an Iranian state-linked campaign using CHOSEN BRICK Windows spyware against dissidents, activists, journalists, and other perceived opponents of the Iranian regime, including victims in the UK, United States, and Netherlands. Active since at least 2025, operators impersonate trusted contacts on WhatsApp and Telegram, cultivate relationships with targets, and deliver tailored malicious files masquerading as legitimate applications or documents; one reported lure used fabricated MRI scan results.
CHOSEN BRICK establishes reboot persistence, weakens Microsoft Defender protections, and uses victim-specific Telegram bots for command and control. It can collect screenshots, microphone audio, emails, files, browser-accessible WhatsApp and Telegram data, and system information, while exfiltrating data through Telegram and cloud object stores and deploying additional malware. The agencies warned that stolen information has appeared on pro-Iranian leak sites, enabling profiling and harassment and potentially increasing targets' physical-safety risks; they released indicators and mitigation guidance.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a technical report on CHOSEN BRICK, accompanying the joint advisory and providing further analysis of the Iranian spyware.
The NCSC, FBI, and Netherlands AIVD issued a joint advisory attributing CHOSEN BRICK spyware activity to Iranian state cyber actors. The advisory detailed tailored WhatsApp and Telegram social engineering, Windows-focused surveillance malware, victim-specific Telegram command-and-control, and risks from stolen data being published on pro-Iranian leak sites.
MI5 Director-General Ken McCallum said British security services had tracked more than 20 potentially lethal Iran-backed plots during the preceding year, including threats against journalists and opponents of the Iranian government.
The FBI linked a July 2025 hack-and-leak operation to Handala Hack, which it assesses operates on behalf of Iran's Ministry of Intelligence and Security and is connected to Homeland Justice.
Iranian state cyber actors began targeting dissidents, activists, and journalists worldwide, including in the United Kingdom, United States, and Netherlands, using the CHOSEN BRICK malware family from at least 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcencsc.gov.uk
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.