UK cyber authorities and international partners warned that Iranian state cyber actors have been tricking dissidents, activists, and journalists into installing spyware called CHOSEN BRICK. The campaign uses impersonation over messaging apps (such as WhatsApp and Telegram), rapport-building, and tailored lures (including fake MRI results) to get victims to download malware that can steal messages, contacts, and capture screens.
How the attack worked
Iranian state cyber actors targeted dissidents, activists, and journalists by impersonating known contacts over WhatsApp and Telegram. Rather than opening with an obvious malicious link, the attackers took time to build rapport with the target, establishing trust before making any request. Once trust was established, victims were encouraged to download software that turned out to be CHOSEN BRICK spyware. In some cases, the lure was highly personal, including fake MRI test results designed to exploit a target's specific interests or anxieties.
Why it succeeded
This campaign worked because it relied on impersonating a trusted contact rather than a stranger or a generic brand. Rapport-building over a familiar messaging app lowered the target's guard before any download request was made. The use of tailored, emotionally resonant content such as medical results made the request feel personal and plausible rather than suspicious. High-risk individuals such as journalists and activists may also feel pressure to respond quickly to messages from contacts, which attackers can exploit.
What to watch for
- Unexpected messages from a known contact on WhatsApp or Telegram that shift from casual conversation to a request to download or install software.
- Files or links that arrive with urgency or emotional weight, such as unexpected medical documents.
- Requests to open or run a file that did not come from an official or verifiable source, even if it appears to come from someone familiar.
- Any prompt to install unfamiliar software following a conversation that started as a normal chat exchange.
How to build resistance
Organizations supporting journalists, activists, and NGO staff should encourage a habit of verifying unexpected download requests through a second channel the target controls, rather than trusting the messaging app alone. Individuals at risk should be aware that attackers may tailor lures to their personal interests or health concerns to increase credibility. Because stolen data from this type of spyware has appeared on leak sites, those who suspect compromise should treat it as a potential safety issue, not just a technical one, and seek specialist support. Security and IT teams supporting at-risk users should reinforce that legitimate contacts rarely need urgent software installs sent directly through chat apps, and that any such request deserves scrutiny before action is taken.
Key findings
- Iranian state cyber actors were observed using spear-phishing and spyware against dissidents, activists, and journalists globally (including the UK).
- Attackers impersonated known contacts over WhatsApp/Telegram, built rapport, then pushed victims to download CHOSEN BRICK spyware.
- Lures were tailored to victims’ interests and included highly personal bait such as fake MRI test results.
- CHOSEN BRICK can steal contacts, emails, and messages and can capture screens and access the device microphone.
- The malware was described as Windows-targeted and persistent (survives reboot), and stolen data has appeared on leak sites.
Who’s being targeted
- Commonly targeted roles: Executives and leadership of NGOs/media, Journalists, Activists, High-risk individuals, Security/IT teams supporting at-risk users.
- Affected industries: Journalism/Media, Non-profits and civil society, Human rights organizations, Political activism and dissident communities.
- Attack channels: whatsapp, telegram.
- Impersonated: A trusted personal/professional contact of the target, A contact sharing purported medical results.
Red flags to watch for
- A contact suddenly pushes you to download/install software via chat
- The conversation quickly shifts from rapport-building to a request to install something
- The download or link is not from an official, verifiable source
- Unexpected medical files/results sent via messaging apps
- Pressure or urgency to open the file immediately
- Medical content arriving from a non-medical account or unverifiable sender
Frequently asked questions
What is CHOSEN BRICK spyware?
CHOSEN BRICK is spyware linked to Iranian state cyber actors that can steal contacts, emails, and messages, and can capture screens and access a device microphone. It is described as Windows-targeted and persistent, meaning it survives a reboot.
How did attackers trick victims into installing the spyware?
Attackers impersonated known contacts over WhatsApp and Telegram, built rapport with the target, then pushed them to download software, sometimes using highly personal lures such as fake MRI test results.
Who was targeted in this campaign?
The campaign targeted dissidents, activists, journalists, NGO staff, and other high-risk individuals globally, including in the UK.
What happens to data stolen by this spyware?
Stolen data, including personal details of some previous victims, has appeared on pro-Iranian leak sites, which can increase personal safety risks for those affected.
Read the video transcript
Iranian state actors are impersonating your WhatsApp and Telegram contacts to plant spyware called CHOSEN BRICK. They chat like a real friend, then drop a link: ‘Hey, install this, it’s the MRI results I mentioned.’ You download it, and CHOSEN BRICK silently starts copying your messages, contacts, screens, even your microphone. A real red flag: a contact suddenly pushes you to download or run software sent over chat, or sends highly personal stuff like medical files from a non‑medical account. That’s how CHOSEN BRICK gets in and stays, even after reboot. If any ‘known contact’ sends software or sensitive files, don’t open it from chat, verify the request through a second channel you control before you touch that download.