US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch agencies have issued a joint warning about ‘Chosen Brick,’ a Windows malware family used by Iranian state actors to spy on dissidents, activists, and journalists. The malware is deployed through social engineering tactics on messaging platforms and is used to gather extensive personal data for surveillance and repression purposes.
US, UK, and Dutch cybersecurity agencies have jointly warned about ‘Chosen Brick,’ a Windows malware family utilized by Iranian state-sponsored actors to target individuals perceived as threats to the Iranian government. The campaign has been active since at least 2025 and is focused on gathering information from dissidents, activists, and journalists worldwide. The malware is deployed through social engineering tactics, primarily leveraging messaging platforms like WhatsApp and Telegram. Attackers initially build rapport with their targets, often posing as acquaintances or technical support representatives, before delivering weaponized files.
Attackers frequently initiate contact through a target’s corporate device, but if enterprise security controls block delivery, they shift the interaction to the individual’s personal device to bypass protections. To trick victims, threat actors disguise malicious installers as legitimate utility software or fake medical documentation, such as MRI scan results. When opened, the file displays a decoy screen while stealthily executing the malware in the background.
Chosen Brick contains extensive surveillance and destructive capabilities, including screenshot capture, host audio recording, browser-stored chat data extraction, email theft, and the deployment of secondary malware payloads. The malware establishes persistence across reboots using registry Run keys and attempts to evade local security tools by adding exclusions in Microsoft Defender. For command-and-control (C&C) operations, the malware assigns each infected endpoint a unique Telegram bot ID to maintain operational security and prevent cross-victim contamination. Exfiltration occurs through the Telegram infrastructure and cloud storage services.
The FBI has separately published a document detailing how Iranian state-sponsored hackers have utilized Telegram as C&C infrastructure in malware attacks targeting the regime’s opponents. While the malware lacks automated lateral movement capabilities, its ability to download secondary payloads allows operators to expand access manually.