US, UK, Dutch Agencies Warn of Iranian Spyware Targeting Dissidents
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have issued a joint advisory warning that Iranian state-linked hackers are using a Windows malware named CHOSEN BRICK to spy on dissidents, activists, and journalists worldwide. The advisory, published on September 15, 2026, details a campaign that has targeted individuals in all three countries since at least 2025. The malware, also identified as HEAVYGRAM by the FBI, is delivered through social engineering on messaging platforms like WhatsApp and Telegram. Attackers often pose as trusted contacts or technical support, building rapport before sending malicious files disguised as legitimate software or fake medical documents, such as MRI scan results. Once opened, the malware installs silently while displaying a decoy interface. CHOSEN BRICK establishes persistence on infected Windows devices by adding itself to Registry Run keys and creates exclusions in Microsoft Defender to evade detection. It uses unique Telegram bots for command-and-control, allowing operators to steal emails, messages, screenshots, and audio recordings.