Structured data rendered for: graph
Back to Blog

CHOSEN BRICK: Iranian Spyware Targets Dissidents

Published
Updated
5 min read
CHOSEN BRICK: Iranian Spyware Targets Dissidents

CHOSEN BRICK: Iranian Spyware Targets Dissidents | 2026

Since September 15, 2026, a joint advisory from the UK's National Cyber Security Centre, the FBI, and the Netherlands' AIVD has put fresh attention on CHOSEN BRICK, a Windows malware family used by Iranian state cyber actors against dissidents, activists, and journalists.

This is not a broad ransomware wave or a commodity loader campaign. It is targeted surveillance, built around patient social engineering, trusted-message lures, and spyware functionality that can expose a victim's contacts, emails, private messages, screen activity, and microphone audio. For people already at risk of transnational repression, that makes the cyber compromise a physical-safety issue too.

The dominant defensive action is not simply "patch this CVE." Security teams should brief high-risk users, search for the described persistence and network indicators, and make sure personal devices are included in the risk conversation when staff, journalists, activists, or community members may be targeted.

What Is CHOSEN BRICK?

CHOSEN BRICK is a malware family described by the NCSC as part of Iranian state-linked cyber activity targeting individuals perceived as threats to the Iranian regime. The advisory says the campaign has targeted people around the world, including in the UK, US, and the Netherlands, and that the activity has been observed from at least 2025.

The malware is designed for collection and surveillance. Once installed, it can gather contacts, emails, social media messages, browser-stored messaging data, screenshots, system details, and audio from the device microphone. The advisory also notes that some stolen personal data from previous victims has appeared on pro-Iranian leak sites, increasing the risk of harassment and personal harm after compromise.

In operational terms, CHOSEN BRICK sits in the threat intelligence category because the most useful response is understanding the attack chain, mapping the indicators, and tuning detection and user support around a specific actor behavior pattern.

Attack Chain

The reported campaign begins with tailored contact over messaging platforms such as WhatsApp and Telegram. Operators often pose as a known contact, a trusted entity, or platform support. The advisory emphasizes that the approach varies by target, but the consistent pattern is rapport first, payload later.

After trust is established, the victim is persuaded to open a file that fits the pretext. Reported lures include applications that appear to be legitimate tools such as Telegram, KeePass, Adobe Flash Player, Norton Antivirus, Pictory, or RunwayML. In other cases, the file has been made to look like MRI scan results. That detail matters because it shows the operators are not relying on generic spam; they are adapting the story to what a specific person may believe.

The file displays something plausible to preserve the deception, while the malware installs in the background. CHOSEN BRICK has been observed targeting Windows systems, persisting through registry Run keys under the current user profile, and using legitimate services such as Telegram for command-and-control.

Why It Matters

The cyber risk here is tightly coupled to real-world harm. If spyware can read a journalist's private messages, copy a dissident's contact list, or record audio from a device, the attacker may gain a map of relationships, routines, locations, and sources. That pattern-of-life intelligence can be used for intimidation, doxxing, or further targeting.

For organizations, the harder part is that the attack may move between corporate and personal devices. The advisory says operators may first approach a work or corporate device, then shift delivery to a personal device if corporate controls make compromise harder. That means a clean corporate endpoint log does not always mean the person is safe.

This is also a reminder that "use secure messaging" is incomplete advice when the attacker is willing to spend time building trust inside those same messaging channels. Phishing defenses need to cover the human conversation before the file arrives, not just the attachment or URL after it is clicked.

Detection Priorities

Defenders supporting high-risk individuals should start by treating CHOSEN BRICK as a device-level compromise risk. Look for suspicious Run key entries under:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

The NCSC advisory lists example value names and paths, but also warns that names and directories can change. Treat the examples as starting points, not a complete signature set.

Network teams should investigate unexpected connections to services observed in the campaign, especially when they do not match normal business use. The advisory highlights domains associated with Telegram API access, cloud object stores, and proxy infrastructure, including api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net.

Endpoint teams should also review Microsoft Defender exclusions, unusual files written under paths made to look like Windows directories, screen capture behavior, suspicious PowerShell or native command usage, and any signs of browser data collection from messaging services.

Mitigation Steps

For individuals at higher risk, the most important control is slowing down the trust handoff. Do not install software, updates, medical files, collaboration tools, or security utilities sent through messaging apps. Navigate directly to the official vendor site or app store instead.

Organizations supporting at-risk staff should combine user guidance with technical controls:

  • Circulate a targeted advisory explaining the CHOSEN BRICK lures in plain language.
  • Enable phishing-resistant multi-factor authentication for corporate accounts.
  • Keep Windows and applications updated through automatic updates where possible.
  • Maintain endpoint monitoring on managed devices and explain what protection does not cover on personal devices.
  • Search for persistence, suspicious network destinations, Defender exclusions, and known indicators across available logs.
  • Prepare an incident response path that includes personal-device guidance, not only corporate ticketing.

The key is to avoid treating this as a purely technical malware note. For targeted people, "ask IT to check your laptop" may be less useful than a clear route to trusted support, preservation of evidence, and safety-aware escalation.

Strategic Takeaway

CHOSEN BRICK shows how state-linked cyber operations can use everyday trust channels as the delivery layer. The attacker does not need a zero-day when a convincing message, a familiar platform, and a personally relevant lure can move the victim to execute the payload.

For security leaders, the lesson is practical: build defenses around the person, not only the managed asset. That means better briefings for high-risk groups, stronger endpoint telemetry where consent and policy allow it, and playbooks that recognize the overlap between cyber compromise, surveillance, harassment, and physical risk.

References

  1. Iranian cyber targeting of dissidents, activists and journalists
  2. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
  3. CHOSEN BRICK technical advisory
  4. Iranian cyber spies used fake MRI scan results to hack enemy of regime

FAQ

How to cite

Lucas Oliveira. CHOSEN BRICK: Iranian Spyware Targets Dissidents. 17 Sept 2026. Invaders Cybersecurity. https://invaders.ie/resources/blog/threat-hunting-and-intel/chosen-brick-iranian-spyware-dissidents.

Subscribe via RSS.

Written by

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.