Iranian spies hit Windows machines with Chosen Brick data-stealing malware
Iranian state-backed hackers are targeting individuals via WhatsApp and Telegram to install surveillance malware called Chosen Brick on Windows devices, according to a joint advisory from the FBI, UK National Cyber Security Centre and the Netherlands' AIVD. The malware has been used since at least 2025 to steal contacts, emails and social media messages, enabling Iran to track the movements of dissidents, activists and journalists; the agencies noted Iranian intelligence has previously plotted kidnappings or lethal operations against perceived enemies abroad.
Attackers conduct extensive research on targets before messaging them while posing as trusted contacts, then persuade victims to open disguised malicious files mimicking apps such as Telegram, Norton Antivirus, Adobe Flash Player and KeePass. Once executed, Chosen Brick survives reboots, evades Microsoft Defender, communicates via a victim-specific Telegram bot, and can capture screens and audio, harvest browser data, download further malware, and wipe systems. The warning comes amid a string of suspected Iran-linked attacks on Western infrastructure, including July's disruption of over 100 US water systems and an August incident that shut down a small UK power plant, though officials have not formally attributed these to Tehran.
- Iran's Chosen Brick malware targets Windows PCs via fake WhatsApp/Telegram messages
- Steals contacts, emails, messages to track dissidents and journalists
- Part of wider suspected Iranian cyberattacks on Western infrastructure