The United States, United Kingdom and Netherlands have issued a joint cybersecurity warning about a spyware campaign that authorities say is linked to Iranian state cyber actors and has targeted dissidents, activists and journalists.
The advisory focuses on a malware family known as CHOSEN BRICK, which the UK National Cyber Security Centre (NCSC), US Federal Bureau of Investigation (FBI) and Netherlands’ General Intelligence and Security Service (AIVD) say has been used against individuals in the UK, US, Netherlands and elsewhere since at least 2025. The FBI separately tracks the malware as HEAVYGRAM.
How the Spyware Campaign Targets People
According to the joint advisory, the campaign begins with targeted social engineering through messaging platforms such as WhatsApp and Telegram. Attackers may impersonate people or organisations familiar to the intended target and spend time establishing credibility before attempting to deliver malicious content.
The agencies said the attackers tailor their approach to individual targets rather than relying on broad, indiscriminate messages. In reported cases, malicious files have been disguised as legitimate software or documents relevant to the recipient, including fake medical information.
The malware has been observed exclusively on Windows systems, according to the NCSC and FBI.
What CHOSEN BRICK Can Collect
The joint advisory says CHOSEN BRICK can collect information including contacts, emails and social-media messages. It also has capabilities involving screen capture and access to the device microphone.
Authorities say the information collected could help attackers build a picture of a target's contacts, activities and movements. In some cases, personal details connected to previous victims have subsequently appeared on pro-Iranian leak sites.
The FBI said the malware has been used for intelligence collection, data leaks and potential reputational harm against intended targets. The agency's March 2026 advisory also linked the campaign to Iran's Ministry of Intelligence and Security (MOIS).
Earlier Activity Linked to the Same Malware
The latest warning follows an earlier FBI disclosure in March concerning malware used against Iranian dissidents, journalists critical of Iran and other opposition groups.
The FBI said the broader activity dates back to at least late 2023. Information obtained during some operations was subsequently associated with the online persona known as “Handala Hack,” according to the agency.
The latest joint advisory provides additional information about CHOSEN BRICK and the methods reportedly used to approach potential victims.
Why WhatsApp and Telegram Matter
The agencies' warning highlights the role of social messaging platforms in the initial stage of the attacks.
Because attackers can use information about a person's professional interests, contacts or activities to make an approach appear credible, an unexpected message may be difficult to distinguish from legitimate communication.
The NCSC says the attackers have been observed impersonating contacts through messaging services and building rapport before attempting to deploy the malware.
Who Is Most at Risk?
The campaign has primarily been associated with Iranian dissidents, activists and journalists, particularly individuals living outside Iran who are viewed by the alleged operators as threats or opponents.
The agencies also caution that the malware could potentially be used against other individuals of interest. The NCSC says organisations should consider staff who may be at heightened risk and ensure they are aware of the advisory.
What High-Risk Users Should Watch For
The advisory highlights the importance of treating unexpected digital communications carefully, especially when a sender attempts to establish trust before asking the recipient to open a file or interact with unfamiliar content.
Users and organisations should independently verify unexpected requests, avoid opening unsolicited files, and ensure security software and operating systems remain properly maintained.
Organisations concerned that a device may have been compromised should seek assistance from their internal or external IT and cybersecurity teams rather than attempting to investigate potentially malicious software themselves.
For organisations handling sensitive financial and operational information, strong documentation and control processes are also important. auditing services in india can help businesses review internal controls and identify areas requiring stronger oversight.
Conclusion
The joint warning from the UK, US and Netherlands highlights a targeted cyber-espionage campaign in which trust and personalised communication are used to reach potential victims. Authorities say CHOSEN BRICK has been used to collect sensitive information from dissidents, activists and journalists through highly targeted approaches on messaging platforms.
The advisory reinforces the importance of verifying unexpected communications and treating unfamiliar files or requests with caution, particularly for people who may face elevated surveillance risks.