TechNewsReel
Live

Allies Expose 'Chosen Brick' Spyware Used by Iran to Target Dissidents

A joint intelligence effort reveals a sophisticated Windows-based malware campaign designed to monitor and repress activists and journalists worldwide.

TechNewsReel Newsroom · September 15, 2026

The FBI, the UK National Cyber Security Centre (NCSC), and the Netherlands' General Intelligence and Security Service (AIVD) have exposed a state-linked Iranian spyware family known as "Chosen Brick." The malware targets Windows systems of dissidents, activists, and journalists globally to facilitate state-sponsored repression.

According to the joint security advisory, the malware has been active since at least 2025. It is deployed through spear-phishing campaigns on WhatsApp and Telegram, where attackers masquerade as legitimate software. Lures often appear as trusted applications, including Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, or RunwayML. Once a user installs the fraudulent app, Chosen Brick establishes persistence on the device via the HKCU Run registry key and adds exclusions to Microsoft Defender to avoid detection.

Technical Capabilities

The spyware is designed for comprehensive surveillance. Confirmed capabilities include the theft of emails, contacts, and social media messages, as well as the ability to capture screen and audio content. In some instances, the malware can be used to wipe the target system entirely. To maintain stealth and prevent victims from discovering one another, the malware utilizes a victim-specific Telegram bot for command-and-control (C2) communications.

Context of Repression

This campaign is part of a broader pattern of Iranian state cyber activity aimed at silencing perceived enemies of the regime. In a joint statement, the FBI, NCSC, and AIVD noted that "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists."

Industry Implications

The ability of Chosen Brick to bypass Microsoft Defender and leverage highly researched social engineering makes it a critical threat to high-profile individuals. Security experts warn that the risk extends beyond digital espionage; the data harvested by the Iranian regime could potentially be used to coordinate physical threats, including lethal operations or international kidnappings of targeted individuals.

What to Watch

As the international community continues to track the Chosen Brick family, investigators are monitoring for updates to the malware's delivery mechanisms. While the current campaign focuses on Windows systems, the evolution of the C2 infrastructure via Telegram bots suggests a flexible approach to evasion. Security agencies continue to urge high-risk users to exercise extreme caution with unsolicited software links on messaging platforms.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.