CHOSEN BRICK: Allied Agencies Expose Iranian Spyware Targeting Dissidents
British, American, and Dutch security agencies have jointly issued a stark warning regarding a new spyware tool, dubbed **CHOSEN BRICK**, employed by Iranian state-sponsored hackers. This sophisticated malware targets individuals perceived as threats to the regime, utilizing extensive social engineering to infiltrate devices and harvest sensitive data.
# Allied Agencies Uncover Iranian Spyware Campaign Against Dissidents
Security agencies from the UK, US, and Netherlands have revealed details of a new spyware tool, **CHOSEN BRICK**, used by Iranian state-sponsored actors. The malware is part of a broader cyber campaign targeting dissidents, activists, and journalists deemed a threat to the Iranian regime.
## The Threat of CHOSEN BRICK
**CHOSEN BRICK**, named by British intelligence, is delivered following extensive social engineering efforts designed to build trust with targets. Lures have included highly convincing fake MRI scans of disk herniations, among other deceptive files.
According to the **United Kingdomβs National Cyber Security Centre (NCSC)**, this and similar cyber activities are used to βsupport the repression of individuals who are seen as a threat to the regime.β The **NCSC** also highlighted that Iranian intelligence services have, in some cases, plotted to kidnap and assassinate perceived enemies of the regime, even internationally.
## Capabilities and Impact
Once installed, **CHOSEN BRICK** grants attackers wide-ranging access to targeted devices. This includes harvesting contacts, email inboxes, social media messages, capturing screen content, and activating the deviceβs microphone.
The collected data can be used to construct a detailed βpattern of lifeβ β a comprehensive map of a victim's location, contacts, and daily routines. This information significantly increases the physical risk to those targeted, with stolen personal details having surfaced on pro-Iranian leak sites to further harass victims.
## A Joint Advisory
The alert was jointly issued by the **NCSC**, the **FBI** in the United States, and the **Netherlandsβ General Intelligence and Security Service (AIVD)**. The advisory covers victims in all three countries, with activity dating back to at least 2025.
Operators behind the campaign tailor their approach to each individual target, leading to variations in initial compromise methods. However, a core pattern involves initial contact via messaging platforms like **WhatsApp** and **Telegram**, often with attackers posing as known contacts or technical support to build rapport before delivering a malicious file.
## Evasion and Persistence
Malicious files are carefully disguised to match the pretext. Beyond the fake MRI scan, attackers have impersonated legitimate products such as **Pictory**, **RunwayML**, **Norton Antivirus**, **Telegram**, **Adobe Flash Player**, and **KeePass**.
**CHOSEN BRICK** specifically targets **Windows** systems. It is designed for persistence, relaunching at login to survive reboots, and adds exclusions to **Microsoft Defender** to evade detection.
For command and control, the malware leverages **Telegram**, assigning a separate bot to each victim to limit exposure if one device is compromised. Stolen files are exfiltrated via **Telegram** and other commercial cloud-storage services. Recent versions of the spyware also employ proxies to conceal network traffic.
The **NCSC** advises organizations with at-risk staff to share this warning and assist employees in checking their personal devices, as attackers may attempt to bypass workplace security by targeting personal devices.
## Attribution and Broader Context
While the **NCSC** did not pinpoint a specific Iranian government entity, the tradecraft aligns closely with activity the **FBI** attributed in a March flash warning. That warning blamed actors operating βon behalf of the Government of Iran Ministry of Intelligence and Securityβ (**MOIS**).
The **FBI** noted similar Telegram-based malware targeting Iranian dissidents and journalists since fall 2023. A July 2025 hack-and-leak operation was linked to β**Handala Hack**,β an online persona assessed to be operated by **MOIS** and connected to another group, β**Homeland Justice**.β
In March, the **U.S. State Department** reissued a $10 million reward for information on hackers connected to Iranian cyber actors, following the compromise of a personal email account belonging to **FBI** director Kash Patel. The same month, the **FBI** seized several leak sites tied to the **MOIS**, used to host stolen victim information.
This cybersecurity warning underscores a significant threat that extends beyond the digital realm. In October 2025, **MI5** Director-General Ken McCallum revealed that British security services had tracked over 20 potentially lethal Iran-backed plots within the preceding year, including threats against journalists and opponents of the Iranian government.
