-
Iranian state-backed hackers use CHOSEN BRICK to spy on dissidents, activists and journalists.
-
The Windows spyware can steal emails, messaging data, screenshots and other data.
-
Attackers use fake apps and documents, such as MRI scans, to trick victims into infecting their own PCs.

Iranian state-backed hackers are using Windows spyware called CHOSEN BRICK to target people viewed as threats to the Iranian regime.
The UK National Cyber Security Centre, FBI and Dutch AIVD disclosed the campaign in a joint advisory on September 15.
The agencies say the victims include dissidents, activists and reporters. Some are in the U.S., U.K. and Netherlands. Some victims have also had private details published on pro-Iranian leak sites.
Attackers Build Trust First Before they Hit
The attacks exploit people’s trust, not any software vulnerability. The hacker contacts their targets through WhatsApp or Telegram, or any other chat app. They gain the victim’s trust by posing as a customer support rep or someone the victim could easily trust.
After the target is comfortable, the hacker sends them a legit-looking file. The files are disguised as various well-known applications such as Pictory, RunwayML, Telegram, Norton Antivirus, Adobe Flash Player, and KeePass.
In another case, the hackers used a fake MRI scan as the lure. The NCSC says hackers often start with a work PC. If that fails, they may ask the victim to use a private Windows PC. This can help them avoid company cyber controls.
CHOSEN BRICK Spyware Hides Behind Fake Apps and Steals Private Data
The files show a screen that matches the story used by the hackers. A fake Pictory installer, for example, can look like the real app. In the background, it gets and runs CHOSEN BRICK.
The spyware then creates a Run key. That makes it start again when the user logs in after a reboot. CHOSEN BRICK can also add skip rules to Microsoft Defender. That can reduce the chance that the antivirus tool will spot its files.
The spyware only targets Windows systems, according to the NCSC. It gives operators several ways to monitor a PC. Also, this spyware is able to collect system information and display active processes. The program can make screenshots and switch the microphone on for audio recordings.
Additionally, it can collect data from Telegram and WhatsApp in web browsers. The spyware can steal email data and get more files to the infected computer. In some cases, it can delete files or wipe the entire system.
Telegram Helps Control Infected PCs
CHOSEN BRICK uses Telegram to control infected PCs. Each victim PC connects to a different Telegram bot ID. The hackers can use the bot to send commands to an infected computer and receive stolen data.
Recent versions use HTTPS and SOCKS5 proxy tools to hide some of their Telegram traffic. However, it can get more spyware and set up persistence for those files. That could support wider attacks, although the NCSC has not observed spread across a network.
The FBI Report Adds more Detail
The FBI released its own technical report on the same day. It reviews spyware that the bureau tracks as HEAVYGRAM. The FBI says Iranian Ministry of Intelligence and Security actors have used HEAVYGRAM since fall 2023. Its report covers seven samples.
The report describes several stages, such as fake apps and spyware that stays. Some samples can collect Chrome, Firefox and Edge data, take screenshots and steal Outlook mail. One sample can also steal Chrome passwords and send them to the hackers.
These details should not be treated as proof that every CHOSEN BRICK sample has every HEAVYGRAM feature. The FBI and NCSC use different names and give separate technical reviews.
Victims Face Risks Beyond Data Theft
The agencies warn that stolen data can expose more than private messages. Screenshots, contacts and other data can help hackers map a victim’s movements and daily life.
The NCSC says private details from some past victims showed up on pro-Iranian leak sites. That can increase the risk of more harassment and real-world harm.
Telegram has also faced separate concerns over alleged data exposure. In another recent case, a massive Telegram data breach claim emerged online, although its authenticity has not yet been verified. The agency also says Iran almost certainly uses cyber activity to support the repression of people it views as threats.
Agencies Urge Checks for Signs of Infection
The NCSC urges checking Windows systems for odd Registry Run entries. It lists examples such as SMQDService and winappx. However, the agency warns that hackers can change file names and Registry values.
Security teams should also review network logs for unexpected links to api.telegram.org, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies.
The agencies urge keeping Windows and other software updated. Users should not install applications they received via messaging or links. The FBI warns users about downloading software from reputable sources, keeping their antivirus software active, and using strong passwords as well as MFA.
The campaign demonstrates the way a message from a trusted source may be a starting point for access to the Windows machine. Careful handling of unexpected files remains key.