Iranian-linked hackers are using Chosen Brick spyware to monitor dissidents, activists and journalists worldwide. The Windows malware exploits Telegram infrastructure to steal messages, files, screenshots and microphone recordings.
Security agencies in the United States, the United Kingdom and the Netherlands have now issued a joint warning about the campaign. In one attack, the hackers even disguised malware as medical MRI results.
Agencies Expose Iranian Espionage Campaign
The FBI’s Internet Crime Complaint Center, the UK National Cyber Security Centre and the Dutch General Intelligence and Security Service published details of the operation.
Investigators have connected Chosen Brick to Iranian cyber activity dating back to at least 2025. However, the FBI has tracked malware from the same family under the name Heavygram since 2023.
The campaign primarily targets people living outside Iran. Its victims include government critics, journalists, activists and other individuals whom Iranian authorities may view as threats.
Chosen Brick has so far targeted Windows computers exclusively. Once installed, it can gather information about a victim’s contacts, emails and social media conversations.
This access may help intelligence operators identify entire networks surrounding one person. Messages and location data can reveal trusted contacts, meetings and relationships that attackers could target next.
Consequently, a single compromised journalist or activist could expose sources and collaborators who never communicated with the hackers.
Hackers Build Trust Before Sending Malware
The attackers begin by researching their intended victim. They then contact the person through encrypted messaging platforms, including Telegram and WhatsApp.
During these conversations, the hackers may impersonate trusted contacts, technical support workers or other convincing identities. Rather than sending malware immediately, they often spend time building a relationship.
Eventually, the attacker sends a malicious file designed to match the established story. The careful preparation makes the download appear authentic and relevant to the conversation.
Researchers have identified fake applications that imitate services and software such as Pictory, RunwayML, Telegram, Norton Antivirus, Adobe Flash Player and KeePass.
In one particularly deceptive case, the hackers sent fake MRI scan results. The medical theme encouraged the victim to open what appeared to be a legitimate and potentially important file.
The operators may also persuade targets to switch from protected workplace equipment to personal computers. Corporate security tools can block suspicious downloads, while personal devices often have fewer protections.
Therefore, security teams should not assume that blocking an attack on a company device ends the operation. The hackers may simply change their communication channel, identity or target device.
Telegram Helps Chosen Brick Avoid Detection
After a victim opens the file, the payload installs additional malware. Chosen Brick spyware then uses Telegram as part of its command-and-control infrastructure.
This approach allows malicious traffic to blend with legitimate communications. As a result, defenders may find it more difficult to distinguish the spyware’s activity from normal Telegram use.
Investigators discovered that the operators assign a separate Telegram bot ID to each compromised device. This measure isolates victims and reduces the risk that investigators can connect one infection to others.
Once active, the malware establishes persistence on the Windows system. It can remain operational after the victim restarts the computer several times.
The spyware supports several surveillance and data-theft functions. It can:
- Capture screenshots
- Record audio through the microphone
- Steal emails and messaging data
- Collect files from the computer
- Download additional malicious tools
- Delete files or wipe data
- Send stolen information through Telegram bots and cloud services
Some information collected during the campaign has reportedly appeared on pro-Iranian leak websites.
Surveillance Creates Risks Beyond Data Theft
Screenshots, messages and recordings can expose much more than passwords or documents. They may reveal a victim’s contacts, location, daily routine and broader pattern of life.
Authorities warn that this information can place other people in danger. For example, stolen conversations could identify confidential sources, fellow activists or relatives who live inside Iran.
The UK describes these operations as transnational repression. The term refers to governments targeting critics and other individuals beyond their national borders.
Around 10 million Iranians are estimated to live outside the country. According to the NCSC, Iranian intelligence services have previously plotted kidnappings and lethal operations against perceived opponents abroad.
Paul Chichester, the NCSC’s Director of Operations, said the campaign showed how Iran uses digital surveillance to repress critics. The attackers seek access to private communications and devices to support that objective.
Iranian Groups Have Targeted Journalists Before
The Chosen Brick campaign forms part of a wider pattern of activity against journalists and government critics.
Iranian-born journalists working for the London-based news organisation Iran International previously faced attacks from Handala. Researchers have linked the group to Iran’s Ministry of Intelligence and Security.
Handala claimed that it had compromised the broadcaster and exposed information connected to 71,000 readers and employees. The alleged stolen material included personal information, staff security details, financial documents and confidential communications.
The group has also claimed several operations connected to the wider Iranian conflict. These included leaks involving defence industry engineers, US Navy officers and thousands of US Marines stationed around the Persian Gulf.
Handala also claimed that it had accessed personal accounts belonging to FBI Director Kash Patel. Telegram has frequently served as a platform for the group’s announcements and threats.
How Potential Targets Can Reduce the Risk
Security agencies are urging people at higher risk to treat unsolicited messages and downloads with caution. A familiar name or convincing conversation does not guarantee that the sender is legitimate.
Potential targets should confirm unusual requests through a separate communication channel. They should also avoid opening unexpected files, particularly when a contact asks them to move the conversation to a personal device.
Authorities recommend installing operating system and application updates promptly. Users should download software only from trusted sources and enable strong authentication wherever possible.
Organisations that support journalists, dissidents and activists should prepare for attackers to move between devices and communication channels. Security testing should account for campaigns that continue after the first attempt fails.
Anyone who suspects an infection should stop using the affected computer for sensitive communication. They should seek professional assistance and preserve relevant messages or files for investigators.
Chosen Brick spyware demonstrates how patient social engineering can turn ordinary conversations into surveillance operations. For high-risk individuals, verifying identities and avoiding unsolicited downloads remain essential safeguards.


0 responses to “Iranian Hackers Use Chosen Brick Spyware Against Dissidents”