Cybersecurity agencies in the US, UK and Netherlands have issued a joint warning about a Windows spyware family dubbed CHOSEN BRICK, used by Iranian state-linked actors to surveil dissidents, journalists and activists worldwide.[2][3][4] The malware, tracked as HEAVYGRAM by the FBI and as CHOSEN BRICK by the UK’s National Cyber Security Centre, is attributed to Iran’s Ministry of Intelligence and Security and has been in use since at least 2025, with related activity dating back to 2023.[2][4][6] Public advisories and reporting highlight a campaign that abuses messaging platforms like WhatsApp and Telegram to deliver the spyware, prompting wider coverage by security outlets including SecurityWeek.[3][9][12]
According to published analyses, Iranian operators initiate contact over social messaging apps, building rapport before sending a malicious file disguised as legitimate software such as Pictory, RunwayML, Norton antivirus, Telegram, Adobe Flash Player or KeePass.[1][4][7] Victims are lured with plausible pretexts, including forged medical documents such as fake MRI test results, and once they open the attachment the spyware installs silently and persists across system reboots.[6][9][11] Dutch intelligence has confirmed that CHOSEN BRICK has already claimed victims in the Netherlands, who have since been notified by the General Intelligence and Security Service.[7]
Once resident on a Windows machine, CHOSEN BRICK gives operators broad surveillance and control capabilities over the victim device.[1][4][6] Analyses describe the malware capturing screen content and audio via the microphone, enumerating running processes, stealing emails and social media messages, harvesting web browser data including saved passwords, and exfiltrating Telegram and WhatsApp information from web sessions.[1][4][10] In some cases it can download additional tools, execute arbitrary commands, delete files, and even wipe the system entirely, effectively destroying evidence and rendering the machine unusable.[1][4] The spyware also adds exclusions to Microsoft Defender in an effort to evade detection by the built-in antivirus on Windows systems.[1][4]
For command-and-control, CHOSEN BRICK relies on Telegram bots, assigning a unique bot identity per compromised user so that discovery of one victim does not expose the full operation.[1][4][5] Joint advisories and media reports describe spear-phishing campaigns on WhatsApp and Telegram, often impersonating trusted contacts or organizations to push the weaponized files.[1][3][9] This approach allows Iranian operators to bypass perimeter defenses and land directly on targets’ personal and professional devices, including those of high-risk communities such as exiled dissidents, human-rights activists and investigative journalists.[2][6][9]
So far, there are no public CVE identifiers or vendor patches specifically tied to CHOSEN BRICK, which appears to rely primarily on social engineering rather than exploiting a particular software flaw.[1][2][4] Research into the broader Telegram malware ecosystem suggests defenders should closely monitor or restrict Telegram bot traffic where it is not needed for business, and treat unusual connections to Telegram APIs as potential exfiltration channels.[13][14] Intelligence agencies in all three countries have encouraged potential targets to report suspicious contact on messaging platforms and to work with trusted organizations to secure their devices and accounts.[3][6][9] Given the campaign’s focus on surveillance and reputational harm instead of immediate financial gain, organizations supporting civil society and media in Iran and the diaspora may need dedicated threat models and protective programs for this spyware family.[2][4][9]
References
- Iranian spies hit Windows machines with Chosen Brick …
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
- UK, US and Netherlands issue advisory on Iran-linked …
- CHOSEN BRICK: Iranian spyware targeting journalists
- Post
- Warning issued after spyware used by Iranian state actors to target dissidents
- AIVD waarschuwt voor malware ingezet tegen activisten en …
- UK, US, Netherlands warn of Iranian spyware targeting …
- Reino Unido, EUA e Holanda emitem alerta sobre spyware ligado ao Irã | CNN Brasil
- بريطانيا وأميركا وهولندا تحذّر من برنامج تجسس مرتبط بإيران
- SecurityWeek: Cybersecurity News, Insights and Analysis
- The Telegram Malware Ecosystem
- Weaponizing Telegram Bots: How Threat Actors Exfiltrate …