NCSC, FBI and AIVD Expose Iranian CHOSEN BRICK Spyware Spread via Fake AI Apps, Utility Installers and MRI-Result Lures
A joint NCSC-FBI-AIVD advisory attributes a Tehran-backed campaign, active since at least 2025, to Iranian state-linked actors deploying the Windows spyware CHOSEN BRICK (FBI tracking name: HEAVYGRAM) against dissidents, activists and journalists via…
A joint advisory published by the UK NCSC, the FBI and the Netherlands' AIVD (reported 2026-09-16; SecurityWeek describes 'joint advisories' from the US, UK and Dutch agencies) attributes a Tehran-backed surveillance campaign, active since at least 2025, to Iranian state cyber actors deploying a Windows spyware tracked as CHOSEN BRICK (FBI tracking name: HEAVYGRAM) against dissidents, activists and journalists worldwide, with reporting specifically citing victims in the UK, US and Netherlands. Delivery is social-engineering based: operators build rapport on social media or impersonate known contacts and platform support staff, approach targets on WhatsApp or Telegram, and push malicious downloads disguised as AI apps (Pictory, RunwayML), Norton Antivirus, Telegram, Adobe Flash Player, KeePass, or fake MRI scan results and application files. Operators reportedly try work devices first, then pivot conversations from targets' corporate devices to personal systems to bypass enterprise controls and EDR. Once installed, the spyware persists via an HKCU Registry Run key, adds Microsoft Defender exclusions, and uses a separate Telegram bot per victim/device for command-and-control, with HTTPS and SOCKS5 proxies concealing C2 traffic; because it touches legitimate web services, it likely appears in corporate DNS and web proxy logs. Capabilities include screen capture, microphone activation and audio recording, theft of emails, contacts, life-pattern information and Telegram/WhatsApp messages, credential theft (per SecurityWeek), process enumeration, command execution, secondary payload downloads, file deletion, and data/system wiping, with data exfiltrated via Telegram, cloud storage and proxy services. In some cases victim data has surfaced on pro-Iranian leak sites for harassment, raising personal-safety risks; the agencies also note Iranian intelligence has plotted kidnappings or lethal operations against targets abroad. The advisory recommends automatic updates, trusted antivirus, phishing-resistant MFA, application allowlisting, and endpoint and network monitoring.
- Joint advisory from the UK NCSC, FBI and Dutch AIVD (SecurityWeek: 'joint advisories' from US, UK, Dutch agencies) ties CHOSEN BRICK (FBI tracking name: HEAVYGRAM) to Iranian state-linked actors.
- Windows surveillance spyware active since at least 2025, targeting dissidents, activists and journalists; reporting cites victims in the UK, US and Netherlands.
- Initial contact via WhatsApp or Telegram by impostors posing as known contacts or platform support staff to push malicious downloads.
- Lures disguised as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass, or fake MRI scan results and application files.
- Operators first engage work devices, then move targets to personal devices to bypass enterprise controls and EDR.
- Persistence via HKCU Registry Run keys; malware adds Microsoft Defender exclusions to evade detection.
- C2 uses a unique Telegram bot per victim/device, with HTTPS and SOCKS5 proxies concealing traffic; activity likely appears in corporate DNS and web proxy logs.
- Capabilities include screenshot capture, microphone activation/audio recording, email theft, Telegram/WhatsApp message theft, contacts and life-pattern harvesting, credential theft (per SecurityWeek), process enumeration, command…
Coverage timelineoldest first · each row is one article
- · 9h agoHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers· 72
NCSC, FBI, and AIVD warn Iranian state-linked actors deliver CHOSEN BRICK Windows spyware via fake AI apps, antivirus installers, and MRI-result lures.
- · 8h agoNCSC and Allies Warn of Iranian Spyware Campaign
Infosecurity Magazine· 76
NCSC, FBI and AIVD warn Iranian-backed actors deliver Chosen Brick spyware to regime critics via social engineering; stolen data has surfaced on pro-Iranian leak sites.
- · 8h agoIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News· 74
Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.
- · 7h agoIranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Help Net Security· 78
UK NCSC, FBI and Dutch AIVD warn Iranian state hackers deploy CHOSEN BRICK spyware via WhatsApp and Telegram lures against dissidents and journalists since 2025.
- · 4h agoUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
SecurityWeek· 60
US, UK, and Dutch agencies warn Iranian state actors deploy Windows surveillance malware 'Chosen Brick' against dissidents, activists, and journalists worldwide.