CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory
NCSC-UK, the FBI and AIVD detail an Iranian spyware family that gives every victim their own private Telegram bot for command and control
Analysis
NCSC UK, the US FBI and the Netherlands' AIVD jointly published a technical advisory on 2026-09-15 for CHOSEN BRICK, a Windows-only malware family Iranian state cyber actors have used since at least 2025 against dissidents, activists and journalists, with confirmed victims in the UK, US and Netherlands (NCSC UK, 2026-09-15). NCSC assesses Iran "almost certainly" uses this activity to support repression of people it perceives as regime threats, and notes Iranian intelligence services have in parallel plotted kidnap or lethal operations against some of the same class of target, framing CHOSEN BRICK as a transnational-repression tool rather than conventional espionage tradecraft (NCSC UK, 2026-09-15). NCSC UK's advisory does not itself name a specific Iranian government entity, but the tradecraft closely matches activity the FBI attributed to actors operating "on behalf of the Government of Iran Ministry of Intelligence and Security" in a flash warning circulated in March 2026, which also linked a July 2025 hack-and-leak operation to the "Handala Hack" persona the FBI assesses MOIS operates and connects to a further group, "Homeland Justice" (The Record, 2026-09-15).
Access begins with extensive social-engineering rapport-building over WhatsApp or Telegram, the actor posing as a contact already known to the target or as platform technical support (T1589, T1566.003). The victim is then persuaded to download and open a file disguised as a legitimate application (observed lures include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass) or as MRI scan results (T1204.002); a decoy screen matching the lure's theme displays while the core malware installs in the background. Operators target the victim's work device first and, if delivery fails or detection risk looks high, pivot to asking the victim to open the file on a personal device instead, sidestepping corporate controls entirely. In every observed instance the malware has targeted Windows only.
CHOSEN BRICK persists across reboot via the registry Run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001), registers a mutex, commonly "ytyjyujyu" or "noi672pp434awkc12f" (T1480.002), and adds Microsoft Defender exclusions to evade detection (T1685). Command and control runs over Telegram, with each victim device assigned its own unique Telegram Bot ID as an explicit operational-security measure to prevent cross-contamination between victims (NCSC UK, 2026-09-15); newer variants layer HTTPS/SOCKS5 proxies over that channel to further obscure it (T1090.002). No automated lateral-movement capability has been observed, though the malware can download and persist additional payloads through the same registry mechanism, making it technically possible.
Tasking supports process and system enumeration (T1057, T1082), screen capture, the most commonly observed data-theft feature, used to map a victim's contacts, location and pattern of life (T1113), microphone capture (T1123), theft of Telegram/WhatsApp browser data (T1005) and email content (T1114.001), and file deletion or a full disk wipe (T1485). Collected data exfiltrates through the Telegram bot (T1041) or cloud object stores such as VultrObjects and StorjShare (T1567.002). NCSC states the most commonly observed additional-malware drop path is C:\Windows \SysWOW64, a non-standard location on most Windows installs because of the deliberate space after "Windows," which NCSC states the actor created specifically for the purpose of deploying malware; in at least one sample, this downloaded payload carried the data-wiping functionality already described above (NCSC UK, 2026-09-15). Some victims' personal data has since surfaced on pro-Iranian leak sites, which NCSC reads as a further harassment vector rather than incidental exposure (NCSC UK, 2026-09-15).
Cited evidence
CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025.
Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.
Once established on the victim, the malware connects to Telegram for Command and Control (T1102.002). Each victim device connects to a different Telegram Bot ID unique to them as an Operational Security precaution, preventing cross-contamination between victims.
The personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.