Image credit: Josh Kirschner/Techlicious generated by ChatGPT
The UK's National Cyber Security Centre, the FBI, and the Netherlands' General Intelligence and Security Service jointly exposed a spyware campaign run by Iranian state hackers against dissidents, activists, and journalists around the world, including in the UK, US, and Netherlands. The malware, which the NCSC calls CHOSEN BRICK, can read a target's messages and emails, turn on the microphone, and grab screenshots of whatever is on the screen, giving the attackers a detailed picture of who the person talks to and where they go.
The joint technical advisory says the campaign has been running since at least 2025 and follows a consistent pattern. An attacker reaches out over WhatsApp or Telegram, posing as someone the target already knows or as tech support for the messaging platform itself. After building up trust, often using details about the target's life gathered in advance, the attacker sends a file and talks the person into opening it.
Those files are disguised as ordinary downloads: video and AI tools like Pictory and RunwayML, security software like Norton Antivirus, Telegram itself, Adobe Flash Player, and the password manager KeePass. In some cases, the attackers even sent fake MRI scan results, betting that a target would open a document appearing to concern their own health. Every version opens a legitimate-looking screen matching the faked software platform while installing CHOSEN BRICK in the background.
Once installed, the malware buries itself in a Windows registry key that runs automatically every time the victim logs in, so it survives a restart. It also adds itself to the exclusion list in Microsoft Defender, Windows' built-in antivirus, so the security software stops scanning it. From there, it checks in with a Telegram bot for instructions (and each infected device talks to a different bot so that discovering one victim doesn't expose the others).
The FBI's own technical report (PDF) on the malware, which it tracks as HEAVYGRAM, attributes the operation to Iran's Ministry of Intelligence and Security and says the goal is to collect intelligence, leak stolen data, and damage the reputations of people the regime views as opponents. That's consistent with what the NCSC has documented elsewhere: personal information taken from past CHOSEN BRICK victims has turned up on pro-Iranian leak sites, and Iranian intelligence services have separately been linked to plots to kidnap or kill people abroad whom the regime considers threats.
"The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices," said Paul Chichester, the NCSC's Director of Operations, in the agency's announcement. He urged people at risk to learn the social engineering tactics described in the advisory and follow its mitigation advice.
The malware only targets Windows, and the advisory notes the attackers often try a corporate device first, then push the target to open the file on a personal device if the corporate security tools get in the way. For anyone worried they might be a target, meaning journalists, activists, or people connected to opposition movements against authoritarian governments, the advisory's core advice is the same guidance that blocks most malware: don't install software sent to you as a link or attachment, even from someone you recognize, and download programs only from the official app store or the vendor's own site instead. Keep your operating system and apps set to update automatically, run antivirus software and keep it current, and never dismiss a Windows SmartScreen warning just because a file looks legitimate.
The NCSC also runs a dedicated support program for high-risk individuals, including free cyber defense services, and the UK government has published separate guidance for anyone who believes they're being targeted by a foreign government. Anyone in the US who suspects they've been hit by this campaign can file a report with the FBI's Internet Crime Complaint Center at ic3.gov.