Breaking
Cyber CrimeDeveloping Story

Iranian Spies Target Windows Users

FBI, UK NCSC, and Dutch AIVD warn that Iranian actors use social messaging apps to deploy Chosen Brick data-stealing malware.

··1 hour ago·4 min read
A laptop with a vibrant colorful screen glowing on a dark wooden desk
Photo by Joshua Woroniecki on Unsplash

Western spy agencies have issued a rare joint warning about an Iranian state cyber campaign that turns ordinary chat apps into a delivery mechanism for surveillance malware. The FBI, the UK's National Cyber Security Centre, and the Netherlands' General Intelligence and Security Service (AIVD) said Iranian actors are targeting individuals on Windows machines, stealing contacts, emails, and social media messages to track people's movements.

Social engineering with deep preparation

According to the advisory, the attacks typically begin with WhatsApp and Telegram messages that appear to come from people or organizations the victim knows and trusts. The Iranian spies do significant research before making contact. By the time they send the first message, they already have what the agencies describe as extensive knowledge of the target, their contacts, and relevant industry organizations, which makes the fake messages more believable.

Once rapport is established, the attackers convince the mark to download and open a file that looks like a legitimate application. The agencies listed the legitimate applications that the malicious files have been made to resemble: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The file executes without the victim's knowledge and remains active after a reboot.

What Chosen Brick does once inside

The malware, tracked as Chosen Brick, has infected Windows systems exclusively in all observed cases. Iran has used it since at least 2025 to take over individuals' devices. The advisory noted that the malware adds exclusions to Microsoft Defender antivirus to evade detection, then connects to Telegram for command-and-control communications using a victim-specific Telegram bot.

Chosen Brick downloads additional malware and sets up persistence for new payloads on infected devices, using the same registry key it uses to establish its own persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Its other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system.

While the malware has not yet been observed to automate lateral movement across a network, the advisory stated that this is technically possible.

“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”

— the FBI, UK National Cyber Security Centre, and the Netherlands' General Intelligence and Security Service (AIVD)

Who is being targeted

The campaign is aimed at individuals, not just corporate networks. Victims are people the Iranian government perceives as threats, including dissidents, activists, and journalists. Because the malware targets personal devices, the agencies recommended that organizations circulate the warning with staff who are likely to be targeted and support them in checking their personal devices too.

The advisory also advised organizations that are concerned Chosen Brick has been executed to contact their IT providers, either internal or external, to investigate.

The broader Iran campaign

The latest alert follows a series of water and energy cyberattacks that researchers and media reports have linked to Iran, although the US and UK governments have stopped short of formally attributing them. In August, America's lead cybersecurity agency, CISA, disclosed that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems. CISA did not attribute the campaign to Iran or anyone else.

Around the same time, a suspected Iran-linked cyberattack also shut down a small UK power plant. Also in August, five US agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned at the time.

What security teams should look for

The advisory describes the technical behavior of Chosen Brick rather than providing a signature list. Security teams should look for an unfamiliar entry in the per-user Run key, Defender exclusions that no administrator added, and outbound Telegram traffic from a device whose owner does not use Telegram for work. The malware also enumerates running processes and system information, captures screen and audio content, and accesses browser-stored Telegram and WhatsApp data.

Because the malware connects to Telegram for command-and-control using a victim-specific bot, detection cannot rely on blocking a single domain. Organizations concerned about exposure should investigate endpoints for the Run key persistence and suspicious Defender exclusions, and check personal devices used by staff who may be at risk.

Why it matters

The joint warning shows that state-sponsored surveillance campaigns are no longer confined to government or corporate networks. The targets here are individuals on personal Windows machines, contacted through the chat apps they use every day. That makes the threat harder for employers to monitor and harder for targets to recognize, because the messages come from accounts that appear to belong to trusted contacts.

The advisory's recommendation to check personal devices as well as corporate ones reflects that reality. For security teams, the practical takeaway is to treat staff who are likely targets as part of the attack surface, even when the compromise happens outside the office network. The campaign also underscores that command-and-control over a widely used messaging platform can blend into normal traffic, leaving behavior-based detection and endpoint visibility as the main defenses.

#iran#chosen brick#malware#windows#cyber espionage

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories