UK, US and Dutch agencies warn of Iranian malware targeting dissidents and journalists

Cybersecurity agencies in the United Kingdom, United States and Netherlands have issued an advisory on CHOSEN BRICK, a malware family linked to Iranian state-backed operators and used against dissiden...

Cybersecurity agencies in the United Kingdom, United States and Netherlands have issued an advisory on CHOSEN BRICK, a malware family linked to Iranian state-backed operators and used against dissidents, activists and journalists internationally.

The UK National Cyber Security Centre (NCSC) said the campaign has targeted people in countries including the UK, US and Netherlands since at least 2025. Officials assess that Iranian authorities use cyber operations to help monitor and repress people viewed as opponents of the regime. The theft of contacts, email and social-media communications may also allow operators to build detailed profiles of victims and potentially track their movements.

According to the advisory, some people previously affected by the malware later had personal details published on pro-Iranian leak sites, raising concerns about possible risks to their physical safety. Iranian intelligence services have previously been accused of planning kidnappings and lethal operations against perceived opponents abroad.

Social engineering tailored to targets

The operators reportedly begin by establishing trust through messaging services such as WhatsApp and Telegram. They may impersonate a known contact or platform support staff, using information gathered about the intended victim to make their approach more convincing.

Victims are then persuaded to open files or install software made to look legitimate. Observed lures have posed as applications including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, as well as purported MRI scan results. The deceptive programs show screens matching their advertised purpose while installing the CHOSEN BRICK payload in the background.

Windows-focused surveillance capability

The malware has been observed targeting Windows devices. It can maintain access after a reboot by creating registry-based startup entries and may attempt to weaken Microsoft Defender protections by adding antivirus exclusions. It communicates with operators through Telegram bots, with separate bot identifiers used for individual victims.

CHOSEN BRICK can collect data and execute commands using built-in Windows tools. Although analysts have not seen it move automatically between systems, it can retrieve additional malware, which could broaden the impact of a compromise.

  • Be cautious of unexpected files and software installation requests sent through messaging apps.
  • Verify identities through an independent channel before opening attachments or following technical-support instructions.
  • Keep endpoint protections enabled and investigate unexplained antivirus exclusions or new startup registry entries.
  • Organisations supporting at-risk individuals should ensure personal devices receive appropriate security guidance and support.