Joint Advisory Exposes Targeting of Iranian Dissidents with Chosen Brick Spyware
By Chris Riotta
September 15, 2026
In a troubling development in the realm of cyberwarfare, a joint advisory has been released by several major intelligence agencies—including the U.K. National Cyber Security Centre, the FBI, and the Netherlands’ General Intelligence and Security Service. This advisory details the use of sophisticated spyware known as Chosen Brick, which has been deployed by Iranian state-sponsored hackers against dissidents, activists, and journalists living outside of Iran. The alarming sophistication of these cyber-attacks poses a substantial threat to the personal safety and security of individuals critical of the Iranian regime.
The nature of the attacks is highly manipulative. Iranian hackers frequently initiate contact through their targets’ work devices, attempting to compromise corporate security systems. When this first attempt proves unsuccessful or too risky, these attackers cleverly redirect their victims to personal devices, where they are prompted to open malicious files. This tactic is particularly worrisome, as it underscores the lengths to which these state-sponsored cybercriminals will go to bypass established security measures.
The advisory underscores the importance of heightened awareness among employees in organizations likely to be targeted. It urges these organizations to disseminate information about the risks associated with Chosen Brick, encouraging staff to conduct checks on their personal devices. This is a critical step in mitigating the risk of exploitation and ensuring the safety of those potentially in the crosshairs of Iranian operatives.
Chosen Brick spyware has been employed since at least 2025, with observed attacks extending to individuals in the U.K., U.S., and the Netherlands, among other nations. This spyware has extensive capabilities, allowing Iranian hackers to extract a wide array of personal information from their targets. Such information includes contacts, emails, and social media interactions; the spyware can even capture screen content. Alarmingly, it can also activate a device’s microphone, providing real-time surveillance capabilities to its operators. The ability to monitor a target’s movements further intensifies the gravity of this threat.
The advisory explicitly states that the Iranian regime likely uses such cyber operations to reinforce its repressive tactics against those perceived as adversaries. Evidence suggests that Iranian intelligence services have not only plotted cyberattacks but have also engaged in more sinister operations in their pursuit of dissidents abroad. Some personal data from former victims of Chosen Brick has indeed appeared on pro-Iranian leak websites, raising concerns about the broader implications of these attacks.
Research into victims is thorough. The advisory notes that operators meticulously gather information about their targets before making contact via popular messaging platforms, such as WhatsApp and Telegram. They often masquerade as familiar individuals or as technical support representatives from these platforms, a tactic that dramatically lowers the defenses of their intended victims. A range of deceptive tactics has been employed, including fake installers masquerading as software from well-known platforms—such as Norton Antivirus, Adobe Flash Player, and even personal health documents.
Once the malicious software is installed on a victim’s device, it employs various techniques to maintain persistence and evade detection, such as modifying Windows registry keys and bypassing Microsoft Defender’s antivirus protections. Each compromised machine shares its information with a dedicated Telegram bot, a strategy designed to prevent cross-contamination among victims.
Although initial findings indicate that Chosen Brick does not exhibit the ability to move laterally within networks autonomously, it has demonstrated the capability to fetch and install additional malware. Alarmingly, the spyware has been known to execute commands for wiping entire systems, revealing the serious potential for broader fallout.
To counteract these threats, cybersecurity professionals advise vigilance against unexpected connections to various legitimate services that the malware exploits, as well as monitoring Windows registry keys for unfamiliar entries. The FBI had previously issued a warning concerning actors linked to Iran’s Ministry of Intelligence and Security, who reportedly utilize Telegram for command-and-control operations related to malware targeting discontented individuals and journalists opposed to the Iranian regime.
For organizations with managed devices, several security recommendations are put forth, including the implementation of phishing-resistant multi-factor authentication and the practice of application allowlisting along with active endpoint monitoring. For individuals managing their own machines, the advisory stresses the importance of downloading software exclusively from official sources and adhering to SmartScreen notifications to avoid the pitfalls of malicious software downloads.
As this advisory highlights, the dynamic nature of cyber threats emanating from state-sponsored entities underscores the essential need for heightened security protocols, awareness, and cooperation among individuals and organizations alike. The specter of persistent cyber threats looms large, marking a critical moment in the ongoing struggle for online safety and privacy.
