Iranian “Chosen Brick” Lures Sent via Telegram

Security Affairs · High sophistication
Last updated September 17, 2026

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical support,” then delivered fake installers or documents (including “MRI scan results”) to trick victims into opening them.

Key findings

  • Attackers contacted targets on WhatsApp/Telegram and “spending time building trust before attempting to deliver malware.”
  • Impersonation was central: the actor “often purports to be an individual previously known to the target or technical support from the social messaging platform.”
  • Malware delivery relied on believable bait files, including “fake installers” for well-known apps and even files “disguised as MRI scan results.”
  • If work-device infection failed, actors tried to move the target to a personal device to bypass corporate controls.
  • Stolen data was exfiltrated via “Telegram bot” infrastructure and cloud object storage (VultrObjects, StorjShare), sometimes hidden with HTTPS/SOCKS5 proxies.

Who’s being targeted

  • Commonly targeted roles: Journalists, NGO staff, Activists/advocacy teams, Executive protection / high-risk users, IT helpdesk (awareness of impersonation).
  • Affected industries: Journalism / Media, Human rights / NGOs, Activists / civil society groups, Government / public sector (dissidents targeted abroad).
  • Attack channels: telegram, whatsapp.
  • Impersonated: Technical support from the social messaging platform (Telegram), Someone the target already knows (friend/colleague/source), Helpful peer/community member or “support” helper in messaging app.

Awareness takeaways

  • Treat unsolicited “support” messages in WhatsApp/Telegram as suspicious, verify via official channels before following instructions.
  • Never install software from chat links/attachments; only use official app stores or vendor websites.
  • Be alert to long-con trust-building and personalized approaches, rapport-building can be part of the attack.
  • High-risk staff should get guidance for personal devices too, because attackers may pivot when corporate controls block them.

Red flags to watch for

  • Unsolicited “support” outreach via chat instead of official support channels
  • Being asked to install software from a direct file/link in a message
  • Pressure to move off a managed work device onto a personal device
  • Unexpected medical or urgent personal file from a chat contact
  • Attachment type/filename looks odd for medical results (e.g., executable/installer)
  • Request to open on a personal device to “make it easier”
  • Software installer delivered via chat instead of official website/app store
  • Decoy screen appears while something else installs silently
  • Unusual instruction to install quickly or ignore warnings
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

The attack doesn’t start in your inbox anymore. It starts in your Telegram or WhatsApp chats. Iran-linked operators chat like normal for days, then: 'Telegram Support: We detected an issue with your account, please install this updated Telegram client to restore secure messaging.' They send a fake installer that quietly drops Windows malware. Or they pose as a friend on WhatsApp: 'Hey, can you take a quick look at these MRI scan results?' The attachment is really an installer, and if your work laptop blocks it, they push you to open it on your personal phone or PC instead. If any 'support' or contact sends software in chat, don’t install it. Stop there and get the app only from the official store or website, never from the message.

Similar attacks

Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations,…

September 15, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026