Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations, then persuade victims to open a file disguised as a legitimate app (for example antivirus or messaging tools). Once installed, the malware can steal messages and emails, capture screen/audio, and maintain persistent access.
How the Attack Worked
The campaign relies on messaging apps that people already trust for personal conversations. Attackers reach out via WhatsApp or Telegram while impersonating a contact or organization the target knows. Before sending that first message, the actors research the target, their contacts, and relevant industry organizations so the conversation feels believable and familiar rather than suspicious.
Once rapport is established, the attacker persuades the victim to download and open a file disguised as a legitimate application. The malicious files have been made to resemble tools like Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, and RunwayML. When the file is opened, the Chosen Brick malware executes quietly and is built to survive a device reboot, giving the attacker continued access.
Why It Succeeded
This approach succeeds because it exploits the trust that already exists between the victim and their real-world contacts. Because the request arrives through a familiar chat thread rather than an unsolicited email, it bypasses the skepticism people typically apply to unknown senders. The extensive research behind each message also means the pretext can reference real people, organizations, or details that make the lure feel personal and credible rather than generic.
The malware itself is also built for stealth. Chosen Brick has been observed infecting Windows systems, stealing contacts, emails, and social media messages, and using Telegram bots for command-and-control. It attempts to evade detection by adding exclusions to Microsoft Defender, reducing the chance that security tools flag the activity.
What to Watch For
- A chat message from a known contact suddenly recommending an app or sending an installer file directly
- Software delivered through a chat conversation instead of an official app store or vendor website
- A period of friendly, rapport-building conversation that precedes a request to install something
- Requests to open a file quickly after that conversation has built trust
Building Resistance
Organizations supporting at-risk staff, including journalists, activists, and traveling executives, should treat any chat-based software install request as high risk. Staff should be trained to verify such requests through a separate, trusted channel and to only download applications from official sources rather than files shared in a chat.
Because this activity targets personal devices as well as corporate ones, organizations should extend awareness guidance beyond the corporate network and support staff in checking their personal Windows computers too. Recognizing grooming behavior, where an attacker builds familiarity before making an ask, is a key part of resisting this kind of social engineering.
Key findings
- Attacks start with WhatsApp/Telegram messages that appear to come from trusted contacts or organizations.
- Actors research targets and their networks to make messages believable and build rapport.
- Victims are convinced to download and open a malicious file disguised as legitimate software (examples include Norton Antivirus, Telegram, Adobe Flash Player, and KeePass).
- Chosen Brick has been observed infecting Windows systems and stealing contacts, emails, and social media messages.
- Malware uses Telegram bots for command-and-control and attempts to evade detection by adding Microsoft Defender exclusions.
- The advisory warns organizations to help at-risk staff check personal devices, not only corporate endpoints.
Who’s being targeted
- Commonly targeted roles: Executive leadership, Communications/PR, Journalists and media teams, NGO/civil society staff, Traveling staff, All employees using WhatsApp/Telegram for work-related communications.
- Affected industries: Journalism and media, Non-profits / civil society (activists, dissidents), Government (targets of state repression), Individuals using personal Windows devices.
- Attack channels: whatsapp, telegram.
- Impersonated: A known and trusted individual or organization (as a WhatsApp contact), A trusted organization/contact on Telegram.
Red flags to watch for
- Unexpected software install request coming via chat instead of official download channels
- A file is sent directly in WhatsApp/Telegram rather than linking to an official vendor site
- Pressure to open an installer quickly after rapport-building
- Software that should be obtained from official websites/app stores is delivered through a chat message
- The request comes after a period of rapport-building (grooming)
- The app name is recognizable, but the delivery method is unusual (a direct file share)
Frequently asked questions
How does the Chosen Brick attack start?
It begins with a WhatsApp or Telegram message that appears to come from someone the victim already knows and trusts, followed by a request to install a file disguised as legitimate software.
What software does the malicious file pretend to be?
The malicious files have been disguised as legitimate applications including Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, and RunwayML.
Who is at risk from this campaign?
Journalists, activists, dissidents, executives, and other staff with public-facing or sensitive roles are the primary targets, and personal Windows devices are affected as well as corporate ones.
What can Chosen Brick do once installed?
It has been observed stealing contacts, emails, and social media messages, and it uses Telegram bots for command-and-control while attempting to evade detection by adding Microsoft Defender exclusions.
Read the video transcript
You get a WhatsApp from a colleague: “Hey, can you install this app? It’s the official Norton Antivirus installer.” Looks normal, right? Iranian state-backed groups are doing exactly this on WhatsApp and Telegram, after researching you and your contacts, sending Windows files that pretend to be Norton, Telegram, Adobe Flash Player, even KeePass. Here’s the twist: when you open that “installer” on your home Windows laptop, it drops Chosen Brick, spyware that steals your emails, social media messages, contacts, and can even record your screen and audio, all controlled over Telegram bots. If anyone sends you an installer over WhatsApp or Telegram, no matter who they claim to be, do not open it. Instead, download the app yourself from the official website or app store and check from there.