Iranian Spies Lure Targets via WhatsApp to Drop Malware

Help Net Security · High sophistication
Last updated September 16, 2026

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI results), infecting Windows devices with CHOSEN BRICK to steal messages, emails, and other sensitive information.

Key findings

  • Attackers initiate contact on WhatsApp and Telegram, impersonating someone the target knows or platform technical support, and build rapport before sending anything malicious.
  • Victims are persuaded to download and open files disguised as legitimate software (e.g., fake Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, KeePass) or even MRI scan results.
  • Attackers often try to get the file opened on a work device first, then push for a personal device if the work environment seems risky or blocked.
  • CHOSEN BRICK targets Windows, aims to evade Microsoft Defender, and persists via registry Run keys.
  • The malware can collect contacts, emails, and social media messages; it can also capture screenshots and turn on the microphone.
  • Captured information has reportedly appeared on pro-Iranian leak sites in some cases.

Who’s being targeted

  • Commonly targeted roles: All staff (messaging-app safety basics), Executives and VIPs, Journalists / communications teams, NGO / advocacy teams, Anyone at elevated personal risk (travelers, public-facing staff).
  • Affected industries: Media and journalism, Non-profits / NGOs, Human rights and activist organizations, Government (individuals abroad).
  • Attack channels: whatsapp, telegram.
  • Impersonated: Someone the target already knows, Telegram technical support, A trusted personal contact (implied) sharing medical results.

Awareness takeaways

  • Treat unsolicited WhatsApp/Telegram messages that try to build trust and then push a download as high risk, verify the sender through a separate, known channel.
  • Never install ‘software updates’, ‘security tools’, or ‘support apps’ that arrive via chat attachments/links, use only official vendor sources.
  • Be cautious about opening sensitive-looking files (e.g., medical results) delivered through messaging apps; confirm authenticity before opening.
  • Share guidance with at-risk staff about personal-device targeting and encourage them to seek help if they think they executed a suspicious file.

Red flags to watch for

  • A contact asks you to install software via a chat link/file instead of an official app store/vendor site
  • Unusual urgency or insistence to open an installer
  • The sender builds rapport and then pivots to a file download
  • “Support” reaches out first through a messaging app
  • Support asks you to run an attached file/installer
  • The file claims to be well-known software (antivirus/password manager) but arrives via chat
  • Unexpected medical/sensitive file delivered via chat
  • Pressure to open immediately without verification
  • File type/format doesn’t match normal medical sharing methods
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

The campaign begins on WhatsApp or Telegram, where someone who looks familiar starts a friendly chat. They build rapport, then drop a file: 'Hey, install this new Pictory video tool' or 'Telegram support needs you to run this security app.' It’s actually CHOSEN BRICK malware for Windows. Once you run it, CHOSEN BRICK dodges Microsoft Defender, sits in your registry, and can quietly grab your emails, chats, contacts, screenshots, even turn on your mic, and that data has shown up on pro-Iranian leak sites. If anyone on WhatsApp or Telegram sends you software or MRI results to open on your PC, stop and verify them through a separate channel before you click.

Similar attacks

Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations,…

September 15, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026