Iranian state hackers spend time building rapport with their targets on WhatsApp and Telegram before sending the file that matters. Sometimes it looks like a video editing tool. Sometimes it looks like the target's own MRI scan results. Behind the convincing screen that opens, a Windows implant the UK's National Cyber Security Centre tracks as CHOSEN BRICK takes over the machine.
The NCSC, the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service (AIVD) published a joint advisory on 15 September naming the malware and its targets: dissidents, activists and journalists in the UK, the US and the Netherlands. CHOSEN BRICK has been in use since at least 2025.
This is surveillance with a physical edge. The NCSC assesses that Iran almost certainly uses cyber activity to support the repression of people it sees as a threat to the regime, and notes that its intelligence services have plotted to kidnap or kill perceived enemies abroad. Personal details of some previous victims have appeared on pro-Iranian leak sites, which the advisory says potentially increases the risk to their safety. "We will continue to call out malicious cyber activity by the Iranian state," said the NCSC's Director of Operations Paul Chichester in the announcement.
The conversation comes first, the file comes later
There is no single lure. The actors research a target in advance, often posing as somebody the target already knows or as support staff from the messaging platform. Observed payloads have impersonated Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, or arrived dressed as MRI test results.
One line in the advisory deserves more attention than it will get. The actors often open on the target's work device, and if that fails, they ask the target to open the file on a personal device instead. The corporate controls are not defeated. They are walked around.
Every victim gets their own Telegram bot
Once running, CHOSEN BRICK persists through the HKCU Run registry key and adds exclusions to Microsoft Defender. Command and control runs over Telegram, and each infected device talks to a different Telegram bot ID, so one burned victim does not expose the rest.
The command set is broad: screen capture, microphone access, Telegram and WhatsApp data pulled from browsers, email theft, further malware, file deletion, and in at least one sample, wiping the system. Screen capture turns up most often, because it hands the operator a target's contacts, location and pattern of life in one go. Data leaves over the Telegram bot and through cloud object stores including VultrObjects and StorjShare. Everything observed has been Windows only.
Check one registry key, then your proxy logs
Start with a single command. Run reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and look at what launches at logon. Entries previously tied to CHOSEN BRICK include SMQDService, pointing into C:\ProgramData\SMQDServicePackages, and winappx, under C:\Users\All Users\MicrosoftDistribution\sysmain. These are examples, not exclusive indicators: names and directories change.
Because the malware leans on legitimate services, it surfaces in DNS and proxy logs. The advisory flags api[.]telegram[.]org, backblazeb2[.]com, vultrobjects[.]com, storjshare[.]io, iproyal[.]com and lightningproxies[.]net as domains worth investigating wherever they appear without a business reason. The rest of the advice is unglamorous: automatic updates on, SmartScreen warnings heeded, phishing-resistant MFA, and application allowlisting on managed devices. The FBI published further technical analysis in a companion report on ic3.gov the same day.
The campaign fits a pattern we have followed all year, including Iranian operations that disguised surveillance tooling as VPN and media apps aimed at the same community, and our Iran country profile has the wider picture. What is different here is the plainness of the advice. Three governments decided the most useful thing they could publish was a registry query and a list of domains, handed straight to the people being watched.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.