CHOSEN BRICK: Iranian spyware aimed at dissidents and journalists
On 16 September 2026, the FBI and the American, British and Dutch cyber agencies described CHOSEN BRICK, Windows spyware used against dissidents, activists and journalists. The stolen data sometimes ends up published online.

On 16 September 2026, the cybersecurity agencies of the United States, the United Kingdom and the Netherlands published a joint advisory, together with the FBI, on a piece of Windows spyware named CHOSEN BRICK. It is attributed to Iranian state-linked actors, and its targets are not companies: they are dissidents, activists and journalists, worldwide but mainly in those three countries. The facts reported here come from Bleeping Computer’s article on the advisory.
A private conversation, then a file to open
The attack starts with a message on WhatsApp or Telegram. The sender poses as a trusted contact or as a technical support agent, and walks the target into opening a file presented as a legitimate application. The lures recorded by the agencies borrow the names of everyday tools: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass. Depending on the pretext used, medical-themed lures have also been observed.
One detail of the method is worth flagging, because it is aimed squarely at people whose employer protects them: the attackers often suggest opening the file on a personal device, so as to get around the security controls on the work machine. The application then displays an interface that matches what was promised, while CHOSEN BRICK installs itself in the background and secures persistence through the Windows registry Run keys.
What the program collects
Once in place, the software adds exclusions to Microsoft Defender to avoid detection, then connects to a single Telegram bot, specific to the victim’s identifier, which serves as its command-and-control channel.
Its capabilities, as listed in the advisory, cover most of what a person does on their machine: system information gathering, enumeration of running processes, screenshots, audio recording through the microphone, theft of email contents and of Telegram and WhatsApp browsing data. It can also download additional payloads into a directory imitating C:\Windows\SysWOW64, delete files, and wipe the host system entirely.
Exfiltration goes through Telegram or through online storage services such as VultrObjects and StorjShare. The most recent variants route their traffic through SOCKS5 proxies to conceal the activity.
The theft does not stop at the theft
This is the part of the advisory that changes the nature of the problem. The stolen data sometimes turns up on pro-Iranian leak sites, which is in itself a form of harassment and raises the physical risk faced by dissidents living abroad. In their advisory, the agencies recall that Iranian intelligence services have, in some cases, plotted kidnappings or lethal operations abroad against people seen as enemies of the regime.
The checks that are recommended
Individuals and organisations who believe they may be exposed are advised to inspect the registry Run entries for suspicious values, and to search their logs for the indicators of compromise published alongside the advisory.
On the network side, the agencies list several destinations to treat as suspicious when a connection to them is not expected: the Telegram API, Backblaze B2, VultrObjects, StorjShare, IPRoyal and LightningProxies.
The most useful piece of advice, though, sits in the entry scenario itself. If someone presses you to open a file on your personal device rather than your work machine, they rarely explain why. Here, the reason is on record.
Sources (1)
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targetsbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


