THE UK, US and Dutch authorities have warned about Chosen Brick, a Windows malware family used by Iranian state-linked actors against dissidents, journalists and activists. In a joint advisory published on 17 September 2026, the UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD said the activity had targeted people in the UK, US and Netherlands, among other locations, since at least 2025.
The malware can collect contacts, emails, social-media messages, screenshots, microphone audio, browser-stored WhatsApp and Telegram chats, and system information. Data from some victims has reportedly appeared on pro-Iranian leak sites, potentially increasing the risk of harassment, intimidation or physical threats.
Attackers typically build trust with targets over WhatsApp or Telegram before sending tailored lures. They may impersonate a known contact or messaging-platform support, and disguise malware as installers for Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass, or as MRI results. A convincing decoy appears while CHOSEN BRICK installs in the background.
The malware persists through a Windows registry Run key, attempts to create Microsoft Defender exclusions, and uses Telegram bots for command and control. Recent variants use HTTPS or SOCKS5 proxies, while stolen data is sent through Telegram and cloud services including VultrObjects and StorjShare. It can download further malware, delete files or wipe a system, although researchers have not observed autonomous lateral spread.
The agencies said observed attacks have targeted Windows systems. Defenders can check for unfamiliar entries under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`, including previously seen names such as “SMQDService” and “winappx”, and hunt for mutexes “ytyjyujyu” and “noi672pp434awkc12f”. Organisations supporting high-risk users should monitor personal devices as well as work equipment and review the published indicators.