> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Iranian CHOSEN BRICK Surveillance Malware: Joint UK/US/Netherlands Advisory
- URL: https://www.thecybersignal.com/iranian-chosen-brick-malware-ncsc-fbi-aivd-2026/
- Published: 2026-09-15T13:00:00.000Z
- Updated: 2026-09-17T01:00:26.000Z
- Description: Three intelligence agencies, one Iranian spyware toolkit, one Telegram channel. UK, US, Netherlands warn this week.
- Author: Nicholas Robert
- Tags: Nation-State Cyber Threats, Malware, Threat Intelligence

Three national security agencies put their names to the same warning this week: an Iranian state spyware toolkit called CHOSEN BRICK has been used to surveil dissidents, activists and journalists, and the people most at risk can take specific steps right now to check whether they have been caught in it.

On September 15, 2026, the UK National Cyber Security Centre (NCSC, part of GCHQ), the US Federal Bureau of Investigation (FBI) and the Netherlands General Intelligence and Security Service (Algemene Inlichtingen- en Veiligheidsdienst, or AIVD) issued a [joint advisory](https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists?ref=thecybersignal.com) attributing the Windows spyware family CHOSEN BRICK to Iranian state cyber actors. The advisory says the toolkit has been used since at least 2025 against people the Iranian regime perceives as a threat in the UK, US and Netherlands, and that it can copy emails and chat messages, take screenshots, and activate an infected device's microphone. The malware is controlled through Telegram.

Here is the part that matters if you are reading this because you might be a target: this is not a vendor blog selling detection. It is three governments telling named at-risk communities that a specific tool has been aimed at them, and pointing to concrete support and mitigation. My assessment, labeled as such, is that the disclosure's real value is the defender playbook attached to it, not the malware's name. Below is what the advisory actually documents, and what individuals and the enterprises that employ high-risk staff should verify today.

## What the Tri-Agency Advisory Documented

The joint advisory attributes CHOSEN BRICK to Iranian state cyber actors and describes it as a Windows spyware toolkit delivered through social messaging apps. The FBI published a separate technical analysis the same day through its Internet Crime Complaint Center ([IC3](https://www.ic3.gov/CSA/2026/260915.pdf?ref=thecybersignal.com)), and the NCSC framed the release as guidance first: advice to help at-risk organisations and individuals detect the activity and reduce the chance their devices are compromised.

The capabilities the agencies attribute to the toolkit are stated plainly. CHOSEN BRICK can collect a target's emails and messaging history, capture what is on screen, and reach the device microphone. The NCSC adds two operational facts that shape any response: the malware has been aimed exclusively at the Windows operating system, and it is persistent, meaning it survives a reboot rather than clearing when the machine restarts. That persistence detail is the difference between a nuisance and a standing surveillance capability, and it is why "just turn it off and on again" is not a remedy here.

On delivery, the advisory keeps to the level a defender needs. Iranian state actors have been observed impersonating trusted contacts over mainstream messaging apps, including WhatsApp and Telegram, and building rapport with a target before the malware is introduced. The actors tailor those approaches to a target's interests, which is the defender-relevant point: an unexpected file or download request from a "known" contact on a messaging app is the moment to slow down, not the technical internals of what runs afterward.

The NCSC put its own assessment on the record. "The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices," said Paul Chichester, the NCSC's Director of Operations, who urged individuals at risk to read the social-engineering techniques in the advisory and act on the mitigation advice. The NCSC also states that it assesses Iran almost certainly uses cyber activity to support the repression of people it sees as a threat, and that personal details of some earlier victims have appeared on pro-Iranian leak sites, raising the physical-safety stakes beyond data theft.

This kind of quiet, long-running, state-run collection is the textbook shape of an [advanced persistent threat](https://www.thecybersignal.com/advanced-persistent-threats-apt-explained-how-they-work/): the goal is to stay resident and keep reading, not to make noise. The leak-site angle also echoes earlier Iranian activity The CyberSignal has covered, including [Iran's MOIS expanding its Handala brand from hacking into recruiting proxies](https://www.thecybersignal.com/iran-mois-handala-brand-hybrid-cyber-physical-operations-2026/), where stolen data was paired with intimidation.

## The Telegram Command-and-Control Channel

The single most reported detail beyond the toolkit's name is that CHOSEN BRICK is run through Telegram. [The Hacker News](https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html?ref=thecybersignal.com) and [SecurityWeek](https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/?ref=thecybersignal.com) both centered their coverage on the Telegram command-and-control (C2) channel, the pathway operators use to send instructions to and pull data from an infected machine.

Why does the C2 choice matter to a defender rather than just an analyst? Because using a mainstream consumer messaging service for command-and-control means the traffic can blend in with ordinary app activity, which complicates the simplest network defense, blocking the attacker's infrastructure. You cannot casually null-route Telegram inside most organizations, and you certainly cannot for an individual journalist who uses it for legitimate reporting. That is an assessment, not a claim from the advisory, but it is the practical consequence of the reported design: detection has to lean on endpoint and behavioral signals rather than a tidy list of malicious domains to block.

Abusing legitimate platforms for C2 is not unique to Iran, and it is worth situating this in the wider pattern. Nation-state operators have repeatedly leaned on trusted services and messaging platforms to reach dissidents, as in the case where [a Signal hijack attempt unspooled into a 13,500-target Russian campaign map](https://www.thecybersignal.com/russian-government-hackers-signal-account-hijack-13500-targets-2026/). The through-line is that the surveillance follows people onto the apps they already trust.

## The Dissidents, Journalists and Activists Victim Set

The advisory is unusually specific about who is in the crosshairs, and that specificity is the point. The named target set is dissidents, activists and journalists who are perceived to pose a threat to the Iranian regime, located in the UK, the US and the Netherlands, though the NCSC notes targeting has reached people around the world.

This is a different threat model from most malware reporting. There is no ransom note, no mass-market credential theft, no botnet. The objective is to know what a specific person is saying, to whom, and where they are, and then, in documented cases, to publish stolen personal details on pro-Iranian leak sites in a way that can translate a digital breach into real-world intimidation. For a journalist, that can mean burning sources. For an activist, it can mean exposing a network of contacts. The consequence of a screenshot or a microphone recording in this context is not measured in dollars.

State surveillance of critics and reporters is a recurring beat, and the tooling varies. This year alone the pattern has run from commercial spyware, as when [Pegasus infected the phone of an MEP investigating spyware](https://www.thecybersignal.com/eu-mep-pegasus-spyware-inquiry-disclosure-2026/), to bespoke state backdoors, as with [Iran-linked Nimbus Manticore deploying the NightLedger backdoor](https://www.thecybersignal.com/nimbus-manticore-nightledger-mirage-kitten-2026/). CHOSEN BRICK sits in that same category of intent, aimed at people rather than payment systems.

## What At-Risk Individuals and Host-Country Enterprises Should Verify

The defender takeaway splits into two audiences, and both have concrete actions in front of them today rather than a vague instruction to stay alert.

**If you are an at-risk individual**, the NCSC's advice is specific. Read the social-engineering techniques described in the advisory so you recognize the impersonation approach, treat unexpected files or download prompts from contacts on WhatsApp and Telegram as suspect even when the sender looks familiar, and take up the NCSC's [dedicated support for high-risk individuals](https://www.ncsc.gov.uk/collection/defending-democracy/guidance-for-high-risk-individuals?ref=thecybersignal.com), which includes free cyber defense services. Because the toolkit targets Windows and persists across reboots, a suspected compromise warrants help from a trusted responder rather than a self-service reboot. If you believe you are the target of a foreign state, the UK also points at-risk people to guidance on transnational repression.

**If you run security for an enterprise that employs high-risk executives or press staff**, three moves map to this advisory:

- **Brief high-risk staff by name.** The people who need this warning are your journalists, your dissident-community liaisons, and executives with a public profile that intersects Iranian interests. Tell them the specific lure: a familiar contact on a messaging app, a tailored pretext, then a file.
- **Review endpoint telemetry against the advisory's indicators.** The FBI's IC3 report and the joint advisory ship indicators of compromise; run them against your Windows endpoint detection data and hunt for the persistence and Telegram-based C2 behavior the agencies describe, rather than waiting for a domain blocklist that a consumer-app C2 will not neatly provide.
- **Restrict unsanctioned messaging-app installs on managed devices.** If Telegram and WhatsApp are not required on a corporate-managed Windows device, controlling their installation shrinks the delivery surface for the impersonation approach the advisory describes.

None of this is exotic. It is asset-owner blocking and tackling aimed at a named, credible, government-attributed threat, which is exactly the kind of warning that justifies moving it to the top of a queue.

## Open Questions

Several things the agencies did not say are worth stating plainly, because the gaps matter as much as the confirmations.

The advisory does not name specific victims, which is appropriate given the population involved but leaves the true scale unclear. It does not attach CHOSEN BRICK to a named Iranian threat cluster, so the tidy label that usually follows this kind of disclosure, an APT number or a vendor cryptonym, is not yet public. And there is no published count of confirmed infections, which means "how widespread is this" has no numeric answer today. The NCSC's "since at least 2025" framing is a floor, not a measured timeline.

Those are not reasons to discount the warning. They are reasons to treat the defensive guidance as the actionable core and to expect the attribution and scope to sharpen as the FBI's technical report is digested. When Iran's cyber posture is the subject, the reporting tends to fill in over weeks, and [Help Net Security](https://www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/?ref=thecybersignal.com), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/?ref=thecybersignal.com) and [The Register](https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646?ref=thecybersignal.com) have all begun tracking the follow-on detail.

| ● Spyware Advisory // CHOSEN BRICK What the NCSC, FBI and AIVD attributed to the toolkit, and what to do about it.                                                                                                                                                                              |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Attributed Capabilities (Per Advisory) Copies emails and chat messages. Takes screenshots. Activates the device microphone. Windows only, and persists across a reboot.                                                                                                                         |
| The Facts The Agencies Agree On Attributed to Iranian state cyber actors. Controlled through a Telegram channel. Delivered via social messaging apps. Aimed at dissidents, activists and journalists in the UK, US and Netherlands since at least 2025.                                         |
| Still Unconfirmed No named victims. No named Iranian threat cluster. No public count of confirmed infections.                                                                                                                                                                                   |
| Defender Move At-risk individuals: take up NCSC high-risk support and read the advisory's social-engineering section. Enterprises: brief high-risk staff, hunt endpoint telemetry against the advisory indicators, and restrict unsanctioned messaging-app installs on managed Windows devices. |
| Source: Joint NCSC, FBI and AIVD advisory on CHOSEN BRICK, September 15, 2026.                                                                                                                                                                                                                  |

*Figure: The capabilities the joint advisory attributes to CHOSEN BRICK, the facts the three agencies agree on, what is still unconfirmed, and the defender response. Source: NCSC, FBI and AIVD, September 15, 2026.*

**Primary documents**

- [NCSC: UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists](https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists?ref=thecybersignal.com) (September 15, 2026)
- [FBI IC3: technical analysis of CHOSEN BRICK](https://www.ic3.gov/CSA/2026/260915.pdf?ref=thecybersignal.com) (September 15, 2026, PDF)