Skip to main content
LiMP VPN
All news

CHOSEN BRICK: Iranian Spyware Reading Emails, Tapping Mics

CHOSEN BRICK: Iranian Spyware Reading Emails, Tapping Mics

In short: On 15 September 2026, the UK National Cyber Security Centre (NCSC), the FBI, and the Dutch intelligence service AIVD published a joint advisory warning about CHOSEN BRICK — spyware attributed to Iran's Ministry of Intelligence. The malware targets journalists, human rights activists and dissidents on Windows devices. It is controlled via Telegram and can steal emails, capture screenshots and secretly activate the device microphone. Victims have been confirmed in the UK, the US, the Netherlands and other countries.

What happened: three intelligence agencies issue a joint warning

On 15 September 2026, the UK NCSC, the FBI and the Netherlands' AIVD published a coordinated technical advisory on a spyware family they call CHOSEN BRICK. The FBI tracks the same malware under the codename HEAVYGRAM. Coordinated public warnings from three countries' intelligence services are rare — a clear signal of the severity of the threat. We track emerging digital threats in the LiMP VPN news section.

The campaign has been observed since at least autumn 2023. According to the advisory, it is attributed to Iran's Ministry of Intelligence and Security (MOIS) — the country's primary intelligence agency. Targets are people whose activities conflict with the Iranian government's interests: journalists reporting on Iran, human rights defenders, political dissidents living abroad, and researchers at think-tanks and government institutions focused on Middle Eastern affairs.

The AIVD confirmed that victims in the Netherlands have been notified, and that data stolen from some of them has surfaced on pro-Iranian leak websites — indicating that this is not intelligence-gathering alone, but targeted harassment and public exposure of individuals.

How CHOSEN BRICK works: technical capabilities

CHOSEN BRICK is Windows-based spyware that persists across reboots and is controlled remotely by operators through a Telegram bot. Documented capabilities include:

  • Email and chat theft — the malware copies sent and received messages from email clients and messaging apps
  • Real-time screenshots — operators can capture the victim's screen remotely at any moment
  • Microphone activation — CHOSEN BRICK turns on the device microphone for covert audio recording
  • Account data harvesting — contact lists, social media message history, and email addresses
  • Security settings manipulation — the malware can change or disable Windows security features to hinder detection

All command-and-control traffic runs through Telegram — an app targets often use legitimately — allowing operators to blend malicious activity into normal usage patterns.

Who is at risk

The advisory identifies the primary target groups. If you fall into any of these categories, the threat is direct:

  • Journalists covering Iranian affairs or critical of the Iranian government
  • Human rights defenders and activists connected to the Iranian diaspora
  • Political dissidents — Iranian nationals living outside Iran
  • Researchers and analysts at institutes and think-tanks focused on Middle Eastern policy

In multiple documented cases, operators constructed highly personalised lures — studying a target's background and interests before crafting a pretext that would seem entirely plausible to that specific person. One recorded example: operators sent fabricated MRI scan results to initiate contact with a medically-connected target.

How the attack unfolds: social engineering through messaging apps

CHOSEN BRICK attacks do not begin with a software exploit — they begin with a conversation. The documented sequence:

  1. Initial contact. Operators create an account impersonating a colleague, fellow journalist, or representative of an organisation familiar to the target. Contact is initiated via WhatsApp, Telegram, or social media.
  2. Building trust. Correspondence continues over days or weeks. The operator offers useful information, requests an interview, or proposes a call — whatever fits the chosen persona.
  3. Malware delivery. The target is asked to download a file disguised as a legitimate application. Documented lures include modified versions of Telegram, KeePass, Adobe Flash Player, and video tools such as Pictory and RunwayML. Fake documents — including fabricated medical results — have also been used.
  4. Persistence and surveillance. Once executed, CHOSEN BRICK installs itself, survives reboots and gives operators persistent remote access to the device.

Note that this attack works regardless of whether the victim uses a VPN. The threat operates at the operating system level and is triggered when the victim executes the malicious file themselves. LiMP VPN encrypts network traffic but does not prevent infections caused by running files from untrusted sources.

Guidance for journalists, activists and researchers

Recommendations from the NCSC/FBI/AIVD advisory:

  • Download software only from official sources. Telegram from telegram.org or official app stores; KeePass from keepass.info. No legitimate contact will send you an installer through a messaging app.
  • Heed Windows SmartScreen warnings. An "unknown publisher" alert when launching a file is a genuine warning, not an inconvenience to click through.
  • Keep your system and antivirus current. CHOSEN BRICK can disable security settings — up-to-date software narrows its ability to do so.
  • Be sceptical of unsolicited contact via messaging apps. Someone you have never met in person asking you to download a file or share your screen is a strong red flag.
  • If you suspect infection, contact law enforcement or a press freedom organisation rather than trying to remove the malware yourself — doing so may destroy forensic evidence.

Network-level protection

Beyond file-handling discipline, network-level protection matters. When you connect to public Wi-Fi at conferences, hotels, or cafés, your traffic — including account credentials — can be intercepted and potentially used as an additional access vector. LiMP VPN encrypts all outbound traffic and operates a strict no-logs policy. See plans starting from $0.99/month.

To be clear about the scope: a VPN does not protect against malware you run yourself. CHOSEN BRICK requires the victim to execute the malicious file — a VPN plays no role at that point. What a VPN does is protect your network traffic from interception and keep your browsing private on shared networks. These are different threats requiring different defences.

Sources

CHOSEN BRICK: Iranian Spyware Reading Emails, Tapping Mics