Iranian Cyber Operatives Target Regime Opponents With 'Chosen Brick' Malware, Western Agencies Warn
A joint advisory from the FBI, NCSC, and AIVD reveals how state-backed actors use social engineering and Telegram-controlled malware to spy on activists, journalists, and dissidents.

A joint cybersecurity warning issued by intelligence agencies in the United Kingdom, the United States, and the Netherlands has highlighted an active Iranian cyber espionage operation targeted at dissidents, activists, and media personnel both domestically and internationally. Operatives associated with Tehran are deploying a specialized Windows malware strain known as Chosen Brick to conduct covert surveillance and steal sensitive data from individuals designated as regime opponents, as first reported by TechRadar Pro.
The formal advisory was published collaboratively by the UK National Cyber Security Centre (NCSC), the Federal Bureau of Investigation (FBI), and the Dutch General Intelligence and Security Service (AIVD). The document outlines a structured operational lifecycle, beginning with meticulous preliminary background research conducted by Iranian state-sponsored actors against targeted individuals prior to any direct technical engagement.
Following the reconnaissance phase, Iranian threat actors initiate direct contact with victims over various social media platforms. To bypass target suspicion, operatives construct fraudulent online identities, presenting themselves either as mutual acquaintances or as technical support personnel representing the specific online platforms the victims utilize. The attackers engage in prolonged digital dialogue to build rapport and lower the target's operational defenses before delivering files containing Chosen Brick.
Engineered primarily to compromise Microsoft Windows operating systems, Chosen Brick possesses a wide range of intrusive capabilities. The malware is capable of enumerating running system processes, compiling detailed system configuration information, capturing real-time screen content, and surreptitiously enabling computer microphones to record ambient room audio. Additionally, the tool extracts localized Telegram and WhatsApp application data directly from web browsers, exfiltrates stored email records, downloads secondary malicious files, selectively deletes documents, and contains functionality to completely wipe the victim's host storage drives.
The threat actors rely on the Telegram messaging service to maintain command-and-control communications with infected endpoints, sending remote instructions and extracting stolen data through the platform. In the joint advisory, the tri-agency coalition noted that Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. The agencies further emphasized that Iranian intelligence services have in some instances plotted to kidnap or conduct lethal operations internationally against individuals perceived as regime adversaries.
Addressing operational countermeasures, the security agencies emphasized that user education and heightened awareness regarding social engineering tactics serve as the frontline defense against these impersonation attacks. Technical recommendations provided by the NCSC, FBI, and AIVD include maintaining automatic system updates across all personal and work hardware, running updated antivirus software, and strictly adhering to automated safety warnings on file downloads, including Microsoft SmartScreen alerts.
For enterprise environments and organizations supporting targeted demographics, the advisory highlights critical infrastructure hardening steps. These mitigation measures include enforcing phishing-resistant multi-factor authentication protocols, applying central management controls to all corporate endpoints, activating automated email security scanning, deploying continuous network and endpoint monitoring solutions, and actively scanning enterprise environments for documented indicators of compromise.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


