Iran-Backed Spyware Uses Fake Support Chats

Infosecurity Magazine · High sophistication
Last updated September 16, 2026

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then push victims to download a “legitimate” app or enticing file (like an “MRI scan”). Stolen emails and messages have reportedly been posted to pro-Iranian leak sites, raising real-world safety risks.

How the attack worked

A Tehran-backed operation uses social engineering, not technical exploits, to get spyware onto a target's device. The threat actor first builds rapport with the victim on social media, usually by impersonating a known contact or posing as social messaging technical support. Once trust is established, the attacker persuades the victim to download something that looks legitimate: a real-sounding app such as Pictory, RunwayML, Norton Antivirus, Telegram, or Adobe Flash Player, or an enticing file like an MRI scan. That download is weaponized to install spyware known as Chosen Brick, which can steal contacts, emails, and social media messages, capture screens and audio, and in some cases wipe the device entirely.

Why it succeeded

The operation relies on borrowed trust rather than malware sophistication at the delivery stage. Impersonating a known contact or a support account removes the skepticism a cold message from a stranger would trigger. Framing the payload as a familiar, well-known app name, or as a sensitive personal file needing urgent attention, gives victims a plausible reason to bypass normal caution. Because targets often use personal devices for sensitive work, requests to install software feel routine rather than suspicious, and there is no formal IT process to flag the request as unusual.

What to watch for

  • Unexpected requests to download or install software arriving through direct chat messages
  • Pressure to install from a link rather than an official app store or vendor site
  • A contact's identity that feels slightly off, even if the conversation otherwise seems familiar
  • Urgent or emotionally charged requests to open a file, such as a medical document
  • Security prompts, smart screen warnings, or antivirus alerts appearing during the download and being dismissed too quickly

Building resistance

Organizations supporting journalists, activists, NGO staff, and other high-risk individuals should treat any in-chat software install request as suspicious by default, verifying it through a separate trusted channel before acting. Staff should be reminded never to click download links or open attachments sent via chat, and to install software only from official vendor sources while heeding, rather than dismissing, security warnings. Because this campaign targets personal devices as much as corporate ones, security guidance needs to extend beyond the corporate perimeter, including help for staff in checking their personal phones and accounts. Finally, organizations should plan for the fact that stolen communications may be exposed on leak sites, which raises both cybersecurity and personal safety considerations for those affected.

Key findings

  • Government advisory warns “opponents of the Iranian regime” (dissidents, activists, journalists) may be targeted by a Tehran-backed spyware campaign.
  • Spyware (“Chosen Brick”) steals contacts, emails, and social media messages; can capture screens and audio and potentially wipe systems.
  • Attackers use social engineering: build rapport on social media by impersonating a known contact or “social messaging technical support.”
  • Victims are persuaded to download a “legitimate app” (examples: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player) or an enticing file (example: “MRI scan”).
  • Stolen information has appeared on “pro-Iranian leak sites,” increasing personal safety risk.
  • NCSC advises avoiding download links/attachments, enabling automatic updates and AV, and not ignoring download warnings; orgs should also help staff check personal devices.

Who’s being targeted

  • Commonly targeted roles: All staff in high-risk roles, Journalists/Editorial teams, Public affairs/Comms, NGO/human-rights teams, Executives who are public-facing, IT/Helpdesk (for guidance on personal-device support).
  • Affected industries: Journalism/Media, Non-profits/NGOs, Human rights organizations, Government (public sector advisories/targets’ host countries).
  • Attack channels: telegram.
  • Impersonated: A known personal contact (impersonated), Social messaging technical support, A known contact (impersonated).

Red flags to watch for

  • Unexpected request to install software coming via chat
  • Pressure to download from a link instead of official app store/vendor site
  • Sender identity feels slightly “off” but relies on trust/rapport
  • Unsolicited support outreach via direct message
  • Support asking you to install software from a chat link
  • Request contradicts normal support processes (no ticket, no official channel)
  • Unexpected sensitive attachment/file from a chat contact
  • Urgency + emotional hook to bypass caution
  • File type or download prompt triggers security warnings
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Chosen Brick spyware?

Chosen Brick is spyware tied to a Tehran-backed campaign that steals contacts, emails, and social media messages, and can capture screens, audio, and potentially wipe systems.

Who is being targeted by this campaign?

Government advisories warn that opponents of the Iranian regime, including dissidents, activists, and journalists, may be targeted, along with staff in high-risk roles who use personal devices for work.

How do attackers trick victims into installing the spyware?

Attackers build rapport on social media by impersonating a known contact or social messaging technical support, then persuade the victim to download a legitimate-looking app or an enticing file such as an MRI scan.

What should organizations do to reduce risk?

NCSC advises avoiding download links and attachments, enabling automatic updates and antivirus, not ignoring download warnings, and helping at-risk staff check their personal devices as well as corporate ones.

Read the video transcript

If you speak out on Iran, assume your DMs are a target, UK agencies say Tehran-backed spyware is hunting dissidents, activists, and journalists. The move is sneaky: on Telegram, someone who looks like a friend or 'Social Messaging Support' chats for a bit, then says, 'Hey, install Pictory or this Norton update from my link.' That link drops the 'Chosen Brick' spyware that can read your emails, social messages, even record screens and audio. Here’s the part people miss: the app name looks legit, Pictory, RunwayML, Telegram, even an 'MRI scan' file, but the install link came in a chat, not from the official app store or vendor site. That tiny detail is the tell. If anyone DMs you to install software or open an 'MRI scan', stop, don’t touch the link. Instead, go to the official app store or vendor site yourself, and if it feels even slightly off, verify with that person or support on a separate channel.

Similar attacks

Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations,…

September 15, 2026
Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026