chosen-brick-spyware

Iranian hackers use Chosen Brick spyware to target Windows systems

Cybersecurity News

FBI, UK NCSC and Dutch AIVD warn Chosen Brick spyware survives reboots and harvests contacts, messages and screen data from compromised systems

Iranian state-linked cyber actors are using popular messaging apps to trick targets into installing surveillance malware on their Windows machines, three Western government agencies warned in a joint advisory published Tuesday.

The FBI, the UK’s National Cyber Security Centre (NCSC) — part of GCHQ — and the Netherlands’ General Intelligence and Security Service (AIVD) identified the malware family as “Chosen Brick.” In every case observed so far, the malware has infected Windows systems exclusively, and the advisory notes it is built for persistence, surviving a reboot of the compromised device.

Once installed, Chosen Brick gives attackers a durable surveillance foothold rather than a one-time data grab. The malware collects a victim’s contacts, emails and social media messages, and includes functionality to capture screen content and access the device microphone — capabilities that let operators track a target’s movements and communications over time.

Social engineering, not exploits, drives initial access

The advisory places heavy emphasis on the campaign’s initial-access method, which relies on sustained social engineering rather than technical vulnerabilities. Iranian actors have been observed impersonating a target’s existing contacts on WhatsApp and Telegram, building rapport over an extended period before delivering the malware payload.

Lures are tailored to individual targets based on personal interests or circumstances. In one case cited in the advisory, attackers used fabricated MRI test results to convince a victim to open malicious content — an approach that underscores how much reconnaissance goes into these operations before a payload is ever delivered.

For enterprise security teams, the technique is a reminder that messaging-app-based social engineering — increasingly common across both nation-state and criminal campaigns — can bypass email-centric phishing defenses entirely, especially when personal devices sit outside corporate mobile device management.

Targets and broader risk

The campaign has targeted dissidents, activists and journalists globally, including individuals in the UK, whom Iran perceives as threats to the regime. The NCSC said data stolen from previous victims has subsequently appeared on pro-Iranian leak sites, a detail that extends the risk beyond conventional espionage: exposed personal data from this kind of campaign can carry physical safety implications for targeted individuals, not just organizations.

“The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime,” the agency said in the advisory.

Paul Chichester, the NCSC’s Director of Operations, said the three agencies would continue to call out malicious Iranian state cyber activity and provide practical defensive guidance. “We strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice,” he said.

Mitigation guidance

The agencies are urging at-risk individuals and the organizations that support them to apply the technical mitigations detailed in the advisory, with particular attention to unsolicited contact impersonation on messaging platforms as a leading indicator of compromise attempts. Security teams supporting high-risk personnel — including journalists, NGO staff, and executives with public profiles — may want to fold these indicators into existing threat-intelligence monitoring and staff security-awareness training.

The NCSC said it has rolled out specialist training on identifying state-threat activity across all UK police forces, and is directing individuals who believe they may be targeted toward its dedicated support programme for high-risk individuals, which includes free cyber defence services.

The advisory was jointly produced by the NCSC, the FBI, and the AIVD, and reflects continued coordination among Western intelligence and law-enforcement agencies in attributing and publicizing nation-state cyber campaigns.

Leave a Reply

Your email address will not be published. Required fields are marked *