Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

The Register Security · High sophistication
Last updated September 16, 2026

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations, then persuade victims to open a file disguised as a legitimate app (for example antivirus or messaging tools). Once installed, the malware can steal messages and emails, capture screen/audio, and maintain persistent access.

How the Attack Worked

The campaign relies on messaging apps that people already trust for personal conversations. Attackers reach out via WhatsApp or Telegram while impersonating a contact or organization the target knows. Before sending that first message, the actors research the target, their contacts, and relevant industry organizations so the conversation feels believable and familiar rather than suspicious.

Once rapport is established, the attacker persuades the victim to download and open a file disguised as a legitimate application. The malicious files have been made to resemble tools like Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, and RunwayML. When the file is opened, the Chosen Brick malware executes quietly and is built to survive a device reboot, giving the attacker continued access.

Why It Succeeded

This approach succeeds because it exploits the trust that already exists between the victim and their real-world contacts. Because the request arrives through a familiar chat thread rather than an unsolicited email, it bypasses the skepticism people typically apply to unknown senders. The extensive research behind each message also means the pretext can reference real people, organizations, or details that make the lure feel personal and credible rather than generic.

The malware itself is also built for stealth. Chosen Brick has been observed infecting Windows systems, stealing contacts, emails, and social media messages, and using Telegram bots for command-and-control. It attempts to evade detection by adding exclusions to Microsoft Defender, reducing the chance that security tools flag the activity.

What to Watch For

  • A chat message from a known contact suddenly recommending an app or sending an installer file directly
  • Software delivered through a chat conversation instead of an official app store or vendor website
  • A period of friendly, rapport-building conversation that precedes a request to install something
  • Requests to open a file quickly after that conversation has built trust

Building Resistance

Organizations supporting at-risk staff, including journalists, activists, and traveling executives, should treat any chat-based software install request as high risk. Staff should be trained to verify such requests through a separate, trusted channel and to only download applications from official sources rather than files shared in a chat.

Because this activity targets personal devices as well as corporate ones, organizations should extend awareness guidance beyond the corporate network and support staff in checking their personal Windows computers too. Recognizing grooming behavior, where an attacker builds familiarity before making an ask, is a key part of resisting this kind of social engineering.

Key findings

  • Attacks start with WhatsApp/Telegram messages that appear to come from trusted contacts or organizations.
  • Actors research targets and their networks to make messages believable and build rapport.
  • Victims are convinced to download and open a malicious file disguised as legitimate software (examples include Norton Antivirus, Telegram, Adobe Flash Player, and KeePass).
  • Chosen Brick has been observed infecting Windows systems and stealing contacts, emails, and social media messages.
  • Malware uses Telegram bots for command-and-control and attempts to evade detection by adding Microsoft Defender exclusions.
  • The advisory warns organizations to help at-risk staff check personal devices, not only corporate endpoints.

Who’s being targeted

  • Commonly targeted roles: Executive leadership, Communications/PR, Journalists and media teams, NGO/civil society staff, Traveling staff, All employees using WhatsApp/Telegram for work-related communications.
  • Affected industries: Journalism and media, Non-profits / civil society (activists, dissidents), Government (targets of state repression), Individuals using personal Windows devices.
  • Attack channels: whatsapp, telegram.
  • Impersonated: A known and trusted individual or organization (as a WhatsApp contact), A trusted organization/contact on Telegram.

Red flags to watch for

  • Unexpected software install request coming via chat instead of official download channels
  • A file is sent directly in WhatsApp/Telegram rather than linking to an official vendor site
  • Pressure to open an installer quickly after rapport-building
  • Software that should be obtained from official websites/app stores is delivered through a chat message
  • The request comes after a period of rapport-building (grooming)
  • The app name is recognizable, but the delivery method is unusual (a direct file share)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the Chosen Brick attack start?

It begins with a WhatsApp or Telegram message that appears to come from someone the victim already knows and trusts, followed by a request to install a file disguised as legitimate software.

What software does the malicious file pretend to be?

The malicious files have been disguised as legitimate applications including Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, and RunwayML.

Who is at risk from this campaign?

Journalists, activists, dissidents, executives, and other staff with public-facing or sensitive roles are the primary targets, and personal Windows devices are affected as well as corporate ones.

What can Chosen Brick do once installed?

It has been observed stealing contacts, emails, and social media messages, and it uses Telegram bots for command-and-control while attempting to evade detection by adding Microsoft Defender exclusions.

Read the video transcript

You get a WhatsApp from a colleague: “Hey, can you install this app? It’s the official Norton Antivirus installer.” Looks normal, right? Iranian state-backed groups are doing exactly this on WhatsApp and Telegram, after researching you and your contacts, sending Windows files that pretend to be Norton, Telegram, Adobe Flash Player, even KeePass. Here’s the twist: when you open that “installer” on your home Windows laptop, it drops Chosen Brick, spyware that steals your emails, social media messages, contacts, and can even record your screen and audio, all controlled over Telegram bots. If anyone sends you an installer over WhatsApp or Telegram, no matter who they claim to be, do not open it. Instead, download the app yourself from the official website or app store and check from there.

Similar attacks

Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026