ZeroHour
Story · 5 sources · 5 articlesfirst updated ()

NCSC, FBI and AIVD Expose Iranian CHOSEN BRICK Spyware Spread via Fake AI Apps, Utility Installers and MRI-Result Lures

highThreat actorexploited in the wildimportance 78
What's new: SecurityWeek (2026-09-16T12:00:14Z), added after the previous summary, corroborates the joint advisory and contributes new detail: CHOSEN BRICK harvests contacts and life-pattern information and supports credential theft, and it frames targets as regime critics/opponents. SecurityWeek also describes 'joint advisories' (plural) from the US, UK and Dutch agencies, while the other four outlets…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint NCSC-FBI-AIVD advisory attributes a Tehran-backed campaign, active since at least 2025, to Iranian state-linked actors deploying the Windows spyware CHOSEN BRICK (FBI tracking name: HEAVYGRAM) against dissidents, activists and journalists via…

A joint advisory published by the UK NCSC, the FBI and the Netherlands' AIVD (reported 2026-09-16; SecurityWeek describes 'joint advisories' from the US, UK and Dutch agencies) attributes a Tehran-backed surveillance campaign, active since at least 2025, to Iranian state cyber actors deploying a Windows spyware tracked as CHOSEN BRICK (FBI tracking name: HEAVYGRAM) against dissidents, activists and journalists worldwide, with reporting specifically citing victims in the UK, US and Netherlands. Delivery is social-engineering based: operators build rapport on social media or impersonate known contacts and platform support staff, approach targets on WhatsApp or Telegram, and push malicious downloads disguised as AI apps (Pictory, RunwayML), Norton Antivirus, Telegram, Adobe Flash Player, KeePass, or fake MRI scan results and application files. Operators reportedly try work devices first, then pivot conversations from targets' corporate devices to personal systems to bypass enterprise controls and EDR. Once installed, the spyware persists via an HKCU Registry Run key, adds Microsoft Defender exclusions, and uses a separate Telegram bot per victim/device for command-and-control, with HTTPS and SOCKS5 proxies concealing C2 traffic; because it touches legitimate web services, it likely appears in corporate DNS and web proxy logs. Capabilities include screen capture, microphone activation and audio recording, theft of emails, contacts, life-pattern information and Telegram/WhatsApp messages, credential theft (per SecurityWeek), process enumeration, command execution, secondary payload downloads, file deletion, and data/system wiping, with data exfiltrated via Telegram, cloud storage and proxy services. In some cases victim data has surfaced on pro-Iranian leak sites for harassment, raising personal-safety risks; the agencies also note Iranian intelligence has plotted kidnappings or lethal operations against targets abroad. The advisory recommends automatic updates, trusted antivirus, phishing-resistant MFA, application allowlisting, and endpoint and network monitoring.

  • Joint advisory from the UK NCSC, FBI and Dutch AIVD (SecurityWeek: 'joint advisories' from US, UK, Dutch agencies) ties CHOSEN BRICK (FBI tracking name: HEAVYGRAM) to Iranian state-linked actors.
  • Windows surveillance spyware active since at least 2025, targeting dissidents, activists and journalists; reporting cites victims in the UK, US and Netherlands.
  • Initial contact via WhatsApp or Telegram by impostors posing as known contacts or platform support staff to push malicious downloads.
  • Lures disguised as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass, or fake MRI scan results and application files.
  • Operators first engage work devices, then move targets to personal devices to bypass enterprise controls and EDR.
  • Persistence via HKCU Registry Run keys; malware adds Microsoft Defender exclusions to evade detection.
  • C2 uses a unique Telegram bot per victim/device, with HTTPS and SOCKS5 proxies concealing traffic; activity likely appears in corporate DNS and web proxy logs.
  • Capabilities include screenshot capture, microphone activation/audio recording, email theft, Telegram/WhatsApp message theft, contacts and life-pattern harvesting, credential theft (per SecurityWeek), process enumeration, command…

Coverage timeline

  1. · 9h ago
    GBHackers· 72
    Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results

    NCSC, FBI, and AIVD warn Iranian state-linked actors deliver CHOSEN BRICK Windows spyware via fake AI apps, antivirus installers, and MRI-result lures.

  2. · 8h ago
    Infosecurity Magazine· 76
    NCSC and Allies Warn of Iranian Spyware Campaign

    NCSC, FBI and AIVD warn Iranian-backed actors deliver Chosen Brick spyware to regime critics via social engineering; stolen data has surfaced on pro-Iranian leak sites.

  3. · 8h ago
    Cyber Security News· 74
    Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware

    Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.

  4. · 7h ago
    Help Net Security· 78
    Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

    UK NCSC, FBI and Dutch AIVD warn Iranian state hackers deploy CHOSEN BRICK spyware via WhatsApp and Telegram lures against dissidents and journalists since 2025.

  5. · 4h ago
    SecurityWeek· 60
    US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

    US, UK, and Dutch agencies warn Iranian state actors deploy Windows surveillance malware 'Chosen Brick' against dissidents, activists, and journalists worldwide.