"Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists," the security advisory said.
How Chosen Brick reaches targets
According to an advisory jointly published by the FBI, the UK National Cyber Security Centre and the Netherlands’ General Intelligence and Security Service (AIVD), attacks using the malware family known as Chosen Brick typically begin with messages sent over WhatsApp and Telegram. Those messages are crafted to appear to come from people or organizations the recipient already knows and trusts. The agencies say the attackers conduct a significant amount of preparatory research so that, by the time the initial message is sent, they already have "extensive" knowledge of the targeted individual, their contacts, and relevant industry organizations.
Victims are social-engineered into downloading and opening files that look like legitimate applications. Files observed in the campaigns have been made to resemble Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass.
Technical behavior: persistence, evasion, and command-and-control
When the malicious file is opened, the advisory says, the malware executes without the victim’s knowledge and survives a reboot. Chosen Brick adds exclusions to Microsoft Defender in an attempt to evade detection, then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot.
To establish persistence — and to set up subsequent payloads — Chosen Brick uses the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The agencies also report that the threat actor downloads additional malware and sets persistence for new payloads using that same key.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageWhat Chosen Brick steals and what it can do
The advisory lists a range of capabilities attributed to Chosen Brick. On infected Windows systems it enumerates running processes and system information; captures screen and audio content; steals emails and social messaging content from web browsers, specifically Telegram and WhatsApp data; and, in some cases, can wipe the computer system. The governments reported that Iran has used Chosen Brick since at least 2025 to take over individuals’ devices and to steal contacts, emails and social media messages — enabling spies to track people’s movements.
Observed limits — and what is technically possible
The agencies note Chosen Brick has only been observed infecting Windows systems and, so far, has not been seen automating lateral movement across a network. Still, the advisory cautions that lateral movement is "technically possible." Separately, the malware’s behavior — persistence across reboots, Defender exclusions, payload downloads, and C2 over Telegram — creates a foothold that can be expanded by follow-on tooling.
What the FBI, NCSC and AIVD recommend
For organizations worried that Chosen Brick may have been executed, the agencies advise: "Organizations that are concerned Chosen Brick has been executed should contact their IT providers, either internal or external, to investigate." The advisory urges organizations to circulate the warning to staff who are likely to be targeted and to "support them in checking their personal devices too," emphasizing that the actor targets personal devices, not just corporate endpoints.
What Chosen Brick means for IT teams, policymakers, and personal-device users
- IT teams and security operators: Expect investigations to include personal devices alongside corporate endpoints, and to look for registry persistence at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Microsoft Defender exclusions, and unusual Telegram-based outbound connections tied to victim-specific bots.
- Policymakers and national security officials: The advisory places Chosen Brick in a broader context of activity that researchers and media have linked to Iran, including recent water and energy cyber incidents; however, the US and UK governments have stopped short of formally attributing those incidents, even as the military conflict between Iran and the US approaches its seventh month.
- Personal-device users and targeted individuals: Be wary of files that mimic legitimate apps and of messages that arrive over WhatsApp or Telegram even when they seem to come from trusted contacts; attackers in these campaigns perform detailed reconnaissance to make their lures convincing.
The joint advisory underscores a blunt reality: intelligence services can and do use tailored social engineering to put surveillance-capable malware onto the personal machines of people they view as threats. For organizations and individuals in the crosshairs, the immediate next step offered by the agencies is practical — check devices, involve IT professionals, and treat personal endpoints as part of the risk profile.




