US, UK, Netherlands Uncover Iranian ‘Chosen Brick’ Malware

US, UK and Dutch agencies warn ‘Chosen Brick’, a Windows malware used by Iranian state actors since at least 2025, is being used to surveil dissidents, activists and journalists worldwide.
Cybersecurity and intelligence agencies in the United States, United Kingdom and the Netherlands issued a joint advisory on Chosen Brick, a Windows malware family used by Iranian state cyber actors since at least 2025 to target dissidents, activists and journalists around the world.
The advisory states the campaign focuses on people perceived as threats to the Iranian regime. Operators collect contacts, emails, social media messages and other personal information that can be used to track locations and daily routines. In some cases, stolen data has been posted to pro-Iranian leak sites to harass targets.
According to the advisory, the attack chain commonly begins on messaging platforms such as WhatsApp and Telegram. Operators research targets to build rapport, often posing as acquaintances or as platform technical support representatives before sending weaponized files. Initial contact often happens on a target’s corporate device; if enterprise protections block the attempt, operators move the interaction to the target’s personal device to bypass those defenses.
Malicious installers are frequently disguised as legitimate utility software or as fake medical documents, including falsified MRI scan results. When a victim opens a file, a decoy screen appears while the malware runs silently in the background. All observed infections so far have targeted Windows endpoints.
Once executed, Chosen Brick creates registry Run keys to persist across reboots and attempts to evade local security tools by adding exclusions in Microsoft Defender. For command-and-control, the malware assigns each infected machine a unique Telegram bot ID to keep communications separate between victims. Data is exfiltrated through Telegram infrastructure and cloud storage services.
The advisory lists the malware’s surveillance and destructive functions: capturing screenshots, recording audio from the host microphone, extracting browser-stored chat data, stealing emails, delivering secondary payloads and executing commands to erase data. The malware does not appear to perform automated lateral movement, but operators can download additional payloads to expand access manually.
The U.S. Federal Bureau of Investigation has separately published guidance describing how Iranian state-sponsored actors have used Telegram as command-and-control infrastructure in attacks against regime opponents. The joint advisory frames Chosen Brick as part of a pattern of activity tied to monitoring and intimidating members of the Iranian diaspora and domestic critics. The campaign adds to a broader pattern of state-backed activity highlighted by recent US charges against 17 Iran-linked hackers accused of targeting universities, companies and government agencies.
The agencies advised that individuals and organizations at risk should be cautious of unsolicited messages on social platforms and apply security controls that prevent successful attacks from moving from managed corporate devices to personal devices.








