THE UK’s National Cyber Security Centre (NCSC), the FBI and the Netherlands’ General Intelligence and Security Service (AIVD) have warned that opponents of Iran’s regime—including dissidents, activists and journalists—may be targeted by a Tehran-backed spyware campaign. An advisory published on 15 September 2026 said stolen information had, in some cases, appeared on pro-Iranian leak sites, creating risks to victims’ personal safety. The campaign has been active since at least 2025.
The spyware, named Chosen Brick, is delivered through social engineering. Attackers build trust on social media, often impersonating a contact or technical-support service, and persuade victims to download apparently legitimate applications such as Pictory, RunwayML, Norton Antivirus, Telegram or Adobe Flash Player, or files such as MRI scans. On Windows devices, Chosen Brick uses registry keys to maintain persistence and adds exclusions to Microsoft Defender to avoid detection.
It communicates with Telegram for command and control, and can collect contacts, emails, social-media messages, system information and running-process data; capture screens; access Telegram and WhatsApp data stored by browsers; record audio through the microphone; download further malware; delete files; or wipe the system.
The advisory recommends that organisations circulate the warning to staff who may be targeted and help investigate personal as well as corporate devices. Legitimate web services used by the spyware may leave evidence in DNS and web-proxy logs. Suggested measures include automatic software updates, trusted and current antivirus, phishing-resistant MFA, application allowlisting, endpoint and network monitoring, and avoiding suspicious downloads or ignored SmartScreen warnings.