Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 16, 2026 · 6 min read

Iran's CHOSEN BRICK Spyware Reads Journalists' Email

On September 15, 2026 the UK's NCSC, the FBI and the Netherlands' AIVD jointly named a Windows implant used by Iranian state actors against dissidents, activists and journalists. Operators impersonate people the target already knows on WhatsApp and Telegram, spend days building rapport, then send a file. One lure was a fake MRI scan showing a disc herniation.

The message does not look like an attack. It looks like a colleague you have spoken to before, on an app you trust, sending something personal. That is the design. The NCSC published the advisory on September 15, 2026, alongside the FBI and AIVD, and the quote from NCSC Director of Operations Paul Chichester is unusually plain: the campaign shows "how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics."

Key Takeaways

  • CHOSEN BRICK is a Windows only implant that the NCSC, FBI and AIVD attribute to Iranian state cyber actors, with victims documented in the UK, the US and the Netherlands since at least 2025.
  • Operators open contact on WhatsApp or Telegram posing as someone the target knows, build rapport over days, then deliver the implant inside files that impersonate Norton Antivirus, Adobe Flash Player, KeePass, Telegram, Pictory or RunwayML.
  • Once running, CHOSEN BRICK harvests contacts, email inboxes and social media messages, captures the screen, and switches on the microphone, surviving reboots via a HKCU\Software\Microsoft\Windows\CurrentVersion\Run entry. Source: NCSC joint advisory
  • Command and control runs through Telegram, with a separate bot per victim, and exfiltration through commodity cloud storage at vultrobjects.com, storjshare.io and backblazeb2.com.
  • Personal details taken from earlier victims have surfaced on pro Iranian leak sites, which the agencies link to a wider pattern of kidnapping and assassination plotting against exiles.

What Is CHOSEN BRICK?

CHOSEN BRICK is a Windows spyware family, named by British intelligence, that Iranian state cyber actors install on the personal computers of dissidents, activists and journalists to read their mail, watch their screens and listen to their rooms. It is not a phone exploit and it is not sold by a commercial vendor. It arrives because a human being agreed to open a file.

That makes it a different animal from the mercenary toolkits that dominate spyware coverage. Pegasus and Graphite are bought, aimed at iPhones, and often land without a click, which is why Apple's threat notifications reached targets in 110 countries this year. CHOSEN BRICK is cheaper and aimed at the machine where you actually write.

The technical picture is unglamorous. Persistence is a registry Run key. Evasion is a Microsoft Defender exclusion. Command and control is api.telegram.org, one bot per victim, so traffic blends into an app half the planet already runs.

A journalist's dimly lit desk at night with an open laptop, a notebook, and a phone face up showing a messaging app, with slats of light from a half drawn blind

How Do Operators Get It Onto a Target's Machine?

They spend days earning the right to send you a file. The attack chain in the joint advisory starts with contact over WhatsApp or Telegram from an account impersonating a trusted entity, frequently someone already in the target's life, followed by ordinary conversation before any payload appears.

The lures are chosen per person. The Record reported that one victim received a fabricated MRI result showing a disc herniation. Others were sent installers wearing the names of Norton Antivirus, Adobe Flash Player, KeePass, Telegram, and the AI video tools Pictory and RunwayML. Note what that list is doing: a password manager and an antivirus product are the two categories a security conscious target installs without a second thought.

This is the third Iran linked social engineering campaign against Windows users we have covered in six months, after Mirage Kitten's fake job offers aimed at engineers in September and the Mabna Institute mailbox theft charges in August. The lure changes. The pretext of a real relationship does not.

Why Does the Advisory Single Out Personal Devices?

Because the operators reportedly approach the work device first, then steer the conversation onto a personal one, specifically to get out from under corporate security controls. The NCSC guidance describes attackers targeting work devices at the outset before transitioning to personal devices to bypass enterprise defences.

That move explains most of the damage. A newsroom laptop has endpoint detection, application allowlisting and someone whose job is to read the alerts. The home machine has none of it, and it holds the same Gmail account and the same Drafts folder. Moving a conversation from Slack to WhatsApp sounds like convenience. Here it is the exploit.

It also means the standard institutional answer, harden the fleet, misses the actual target: freelancers, stringers and exiled reporters have no fleet at all. The NCSC instead points high risk individuals at its own free services, including guidance for high risk individuals and an invitation based Personal Internet Protection service that blocks known malicious domains on personal devices.

What This Means for Your Inbox

Read the capability list again and notice the order: contacts, emails, social media messages. The mailbox is not collateral here, it is the objective. Everything the microphone and the screen capture add is context around a body of correspondence the operators already have.

For a reporter, the address book is the story. One export of contacts plus a year of threads tells an intelligence service who talks to you, how often, and which of those people stopped replying after a sensitive piece ran. Encryption on the wire does nothing about it, because the implant reads messages after decryption, on the endpoint, exactly where you read them. Agencies call the result a "pattern of life" that maps a person's location and routine.

Then it stops being a data problem. Details from earlier CHOSEN BRICK victims have been published on pro Iranian leak sites, and the FBI has tied related activity to the Handala Hack persona, the same brand that surfaced when Iran linked hackers wiped roughly 200,000 servers at a medical device maker. Collection and publication run through the same machinery. Your correspondence is harvested for the state and dumped for the mob.

What Should You Do This Week?

Most of the countermeasures in the advisory are behavioural, not technical, because the intrusion is behavioural.

  • Verify out of band before opening anything. If a known contact sends you a file over WhatsApp or Telegram, confirm on a channel you established separately. Impersonating a real contact is the opening move, so the sender's identity is exactly what you cannot trust.
  • Never install software from a chat window. Norton, KeePass, Telegram and Flash Player all have official distribution. A link in a conversation is not one of them.
  • Turn on phishing resistant MFA. Hardware keys or passkeys on your mail account limit what a stolen session or credential is worth after the fact.
  • Check your Defender exclusions. An exclusion you did not create is the cleanest single indicator in the advisory, and it takes thirty seconds to look.
  • Audit Gmail for the quiet persistence. Forwarding addresses, filters that auto archive, app passwords and connected apps outlive any malware cleanup.
  • Report it. UK targets can use the NCSC reporting service; US targets should file with the FBI's IC3.

If you believe you are already compromised, treat the mailbox as the priority, not the laptop. Reinstalling Windows removes the implant. It does not remove a rule someone else added to your Gmail six months ago.

The Ordinary Tools Are the Point

There is no zero day in this story. No exploit chain, no vendor, no seven figure licence. A Telegram bot, a registry key, a Defender exclusion and a stranger who learned enough about your life to fake your MRI results. Three intelligence agencies wrote a joint advisory about it because that combination keeps working against people whose safety depends on it not working. The most sophisticated part of CHOSEN BRICK is the conversation that precedes it, and no patch ships for that.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.