“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said NCSC director of operations, Paul Chichester.
Who issued the warning and who it targets
An advisory published by the UK’s National Cyber Security Centre (NCSC), the FBI and the Netherlands' General Intelligence and Security Service (AIVD) warns that opponents of the Iranian regime may be subject to targeting by a Tehran-backed spyware campaign. The advisory is explicitly designed to help dissidents, activists and journalists critical of the regime, and notes that information stolen by the spyware has, in some cases, appeared on pro-Iranian leak sites — increasing risk to victims’ personal safety.
Chosen Brick: capabilities and persistence
The campaign centers on malware the agencies call Chosen Brick. According to the advisory, Chosen Brick is designed to harvest targets’ contacts, emails and social media messages and to enable tracking of movements and other forms of repression. On infected Windows devices it uses registry keys for persistence and adds exclusions to Microsoft Defender to evade detection.
Its reported functionality is broad: it enumerates running processes and system information, takes screen captures, harvests Telegram and WhatsApp data from browsers, steals emails and can enable the device microphone for audio capture. The spyware can also delete files, download additional malware and wipe an entire system. For command-and-control (C2) the malware connects to Telegram.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageDelivery: social engineering and legitimate-looking downloads
The advisory says the actor delivers Chosen Brick through social engineering. Attackers build rapport on social media, commonly by impersonating a contact or posing as social messaging technical support, and then persuade targets to download a seemingly legitimate app or file. Examples named in the advisory include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and files presented as an MRI scan.
NCSC advice for targets and organizations
The NCSC and its partners offer specific operational advice. Organizations concerned about infection are urged to contact internal or external IT providers to investigate, and to circulate the advisory to staff likely to be targeted — because the actor focuses on personal devices as well as corporate ones. The advisory highlights a defensive opportunity: because Chosen Brick interacts with numerous legitimate web services, it is likely to appear in corporate DNS and web-proxy logs.
- Follow NCSC advice on staying safe online, including avoiding clicking on download links or attachments.
- Switch on automatic updates for device operating systems and software.
- Enable trusted antivirus and ensure it is up to date; do not disable or ignore smart-screen warnings on file downloads.
- Network administrators should consider phishing-resistant multi-factor authentication, managing and protecting device fleets with antivirus and app allowlisting, and installing endpoint and network monitoring.
How technologists, affected enterprises, and end users should respond
Technologists and security teams should hunt for C2 traffic to Telegram and anomalous exclusions being added to Microsoft Defender, and review DNS and web-proxy logs for interactions with legitimate services that Chosen Brick abuses. Affected enterprises and procurement leaders should ensure incident-response pathways include checks of employees’ personal devices and circulate the advisory to staff likely to be targeted. End users — particularly dissidents, activists and journalists named as at-risk in the advisory — should be cautious about social-media contacts that request downloads, keep device OS and apps current, and use trusted antivirus and phishing-resistant MFA where available.
The NCSC says the campaign has been running since at least 2025. Its advisory is both a technical notice and a public-safety alert: when stolen material appears on pro-Iranian leak sites, the tactical effect goes beyond data loss to increased personal risk. The agencies’ core prescription is straightforward and practical — harden devices, watch corporate logs, and treat unsolicited download requests on social media as potentially life-threatening traps.
Original advisory: https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/



