Summary
- UK, US, and Dutch authorities have detailed CHOSEN BRICK malware used against dissidents, activists, and journalists since at least 2025.
- The Windows malware can collect communications, capture screens and audio, and use legitimate online services as part of its infrastructure.
- The NCSC assesses that Iran almost certainly uses the activity to support repression, while some previous victims’ personal information has appeared on pro-Iranian leak sites.
UK, US, and Dutch authorities have exposed an Iran-linked spyware campaign targeting dissidents, activists, and journalists, including people in Britain, connecting device compromise with wider concerns over surveillance and transnational repression.
The UK National Cyber Security Centre, the US Federal Bureau of Investigation, and the Netherlands’ General Intelligence and Security Service, the AIVD, have detailed a Windows malware family tracked by the NCSC as CHOSEN BRICK. The agencies say it has been used against targets around the world since at least 2025.
The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of people regarded as threats to the Iranian state. That attribution is an intelligence assessment. The agency also says personal details belonging to some previous victims have appeared on pro-Iranian leak sites, potentially extending the consequences of compromise beyond the affected devices.
CHOSEN BRICK is delivered through highly tailored social engineering. Operators have approached targets through messaging services including WhatsApp and Telegram, sometimes impersonating known contacts or technical-support personnel and building rapport before attempting to persuade the victim to open a malicious file.
The lures have imitated legitimate applications including Telegram, KeePass, Norton Antivirus, RunwayML, and Pictory. In other cases, attackers have used files presented as MRI scan results. Once opened, the material displays content intended to preserve the deception while installing the malware in the background.
The malware establishes persistence on Windows systems and can collect emails, social-media messages, screen captures, audio, system information, and other files. It can also download additional malware. The NCSC says legitimate online services, including Telegram infrastructure, have been used as part of the operators’ command-and-control activity.
The campaign also shows how security boundaries around high-risk individuals extend beyond managed corporate hardware. The NCSC says operators have initially approached some targets through work-related or corporate devices, but moved towards personal equipment where the initial delivery failed or corporate controls increased the risk of detection.
That creates exposure that conventional enterprise controls cannot fully contain. Journalists, researchers, officials, executives, and activists targeted because of their work can carry risk between managed and unmanaged environments, while information taken from personal devices can reveal contacts, communications, location patterns, and professional relationships.
Paul Chichester, Director of Operations at the NCSC, said the activity involved attackers “stealing emails and messages and accessing devices”. The agency has released technical indicators and defensive guidance alongside support intended for people considered at heightened risk from state threats.
The operational consequence of targeted spyware can extend beyond confidentiality. Information taken from devices may contribute to surveillance, coercion, harassment, or physical targeting where victims are already of interest to a state. The NCSC says Iran has previously been linked to plots against people overseas whom its authorities perceive as enemies.
The agencies have not disclosed how many people were successfully compromised, and an approach by the operators does not establish that malware was installed. The confirmed picture is narrower: CHOSEN BRICK has been observed targeting individuals internationally, including in the UK, and the NCSC assesses that the activity supports a broader Iranian effort against critics of the regime.





