The file looked like an MRI scan. Lumbar spine, several grey slices of vertebrae, a heading reading something like ‘Disk Herniation and Degeneration.’ For a dissident living in exile – someone with a body that has been through things, someone waiting on results – it was a plausible thing to open.
Opening it handed Iranian intelligence the microphone.
That lure, reproduced in a joint advisory published Monday by Britain’s National Cyber Security Centre, the U.S. Federal Bureau of Investigation and the Netherlands’ General Intelligence and Security Service, is one of several used to deliver a spyware family the NCSC has named “CHOSEN BRICK.” The three agencies say Iranian state cyber actors have used it since at least 2025 against dissidents, activists and journalists worldwide, including in all three of their countries.
What makes the campaign notable is not its technical sophistication. By the standards of state espionage, CHOSEN BRICK is unglamorous – Windows only, no automated spread, command-and-control running over Telegram bots. What makes it notable is the patience of the human work wrapped around it, and what appears to happen to the data afterward.
The operators do not spray phishing links. They research a target, then open a conversation on WhatsApp or Telegram posing either as someone the target already knows or as technical support from the messaging platform itself. Then they talk. The advisory describes rapport-building as a distinct phase of the attack chain, drawing on what it calls extensive target knowledge gathered in preparation.
Only after that does a file arrive, themed to whatever the conversation has been about — a video tool like Pictory or RunwayML, a password manager, an antivirus installer, medical results. Open it and a convincing screen appears: a real-looking Pictory login page, a real-looking scan. Behind it, the implant installs.
The single most telling detail in the advisory is a paragraph about which device gets hit. The actors often approach a target’s work computer first. If that fails, or if detection looks likely, they ask the target to open the file at home instead – deliberately steering the victim off a monitored corporate machine and onto the personal laptop where nobody is watching. That is not a technical exploit. It is an understanding of how a journalist’s life is actually configured.
Once installed, the malware survives reboots through a registry run key, writes itself Microsoft Defender exclusions, and reports to a Telegram bot. It can enumerate running processes, grab the screen, switch on the microphone, lift Telegram and WhatsApp session data out of browsers, pull email, download further payloads and delete files. The NCSC says one sample also carried data-wiping functionality, though the FBI’s own 55-page technical breakdown, published the same day, documents no wiper.
Two design choices stand out. First, each infected device talks to its own unique Telegram bot ID — an operational security measure, the advisory notes, to prevent cross-contamination between victims. The people hunting dissidents are careful to compartmentalize their victims from one another.
Second, one payload documented by the FBI kills the real WhatsApp process and substitutes a trojanized copy, rewriting the desktop shortcut to point at it. The victim keeps using WhatsApp. WhatsApp keeps working. Another sample dumps entire Outlook mailboxes, attachments included, to a zip archive. Others stage screen and audio recordings into password-protected archives before shipping them out through Telegram or cloud object storage.
The FBI calls the same malware HEAVYGRAM, and goes considerably further than its British counterpart on attribution. Its report states plainly that the activity is conducted “on behalf of the Government of Iran’s Ministry of Intelligence and Security” — MOIS. The NCSC advisory says only “Iranian state cyber actors.” That gap between two co-signing agencies is unusual enough to be worth noticing.
Espionage against exiles would be alarming enough. The advisory’s quietest sentence is the one that should worry readers most: personal details of some previous CHOSEN BRICK victims have turned up on pro-Iranian leak sites.
That is the hinge between surveillance and harm. A stolen contact list is not just intelligence; published, it is a map of everyone a dissident in London still speaks to in Tehran. In May, Global Affairs Canada documented a July 2025 hack-and-leak by the Iran-linked Handala persona that exposed five Iran International staff — passports, driver’s licences, permanent resident cards, email passwords, and intimate photographs — then amplified the material across social platforms. The U.S. Justice Department seized four Iranian-linked leak and harassment domains in March 2026, and the FBI has separately assessed that some data posted by Handala was obtained using this malware. No public document yet ties the Iran International leak specifically to CHOSEN BRICK, but the timelines converge uncomfortably.
Read: Iran-Linked Handala Hackers Launch New Domain Hours After FBI Seized the Older One
Paul Chichester, the NCSC’s director of operations, said the campaign shows how Iran “ruthlessly uses digital surveillance in pursuit of its aim to repress critics,” urging those at risk to study the social-engineering patterns described and act on the advice. Dutch intelligence said victims in the Netherlands have been informed. No agency published a victim count, and none should be inferred.
The reason a spyware advisory about contact lists and screenshots reads like a physical-safety story is that, in this particular threat model, it is one.
Ruhollah Zam ran a Telegram channel with more than a million followers from exile in Paris. In October 2019 he was lured to Iraq with the offer of an exclusive interview, seized on arrival, and hanged in December 2020. Masih Alinejad, the Iranian-American journalist, survived both a plot to render her out of New York and a murder-for-hire attempt; two men were sentenced to 25 years each in October 2025. Pouria Zeraati, an Iran International presenter, was stabbed outside his London home in March 2024; two men were jailed at the Old Bailey in July 2026, where the judge found the attack was carried out for the benefit of a foreign power.
MI5 Director General Sir Ken McCallum said in his October 2025 threat update that the service had tracked “more than 20 potentially lethal Iran-backed plots” in a single year — roughly matching the total for the preceding three.
Against that backdrop, a stranger’s warmth on WhatsApp and a file that looks like your scan results are not a nuisance. They are reconnaissance. The advisory’s most practical instruction is also its bluntest: do not let a persuasive contact move you onto the device where no one is watching.