UK and allies warn of Iranian spyware campaign targeting dissidents, activists and journalists
The UK’s National Cyber Security Centre (NCSC), working with intelligence agencies in the United States and the Netherlands, has warned of an Iranian cyber campaign targeting dissidents, activists and journalists around the world, including individuals in the UK.
The agencies have published technical details of a Windows malware family known as CHOSEN BRICK. The malware has been used by Iranian state-linked cyber actors to gather sensitive information from targeted individuals, with activity observed since at least 2025.
According to the NCSC, the attackers rely heavily on social engineering rather than simply attempting to exploit technical vulnerabilities. Targets are contacted through messaging platforms such as WhatsApp and Telegram, with attackers often impersonating people the victim already knows or trusted technical support services.
The attackers can spend time building a relationship with their targets before attempting to deliver the malware.
Malicious files are then disguised as legitimate software or documents. The NCSC says observed lures have included fake versions of applications such as Telegram, Norton Antivirus, KeePass, Pictory and RunwayML. In another example, attackers used fabricated MRI scan results as part of their approach.
Once opened, the malicious file presents the victim with content designed to appear legitimate while CHOSEN BRICK is installed in the background.
The malware can establish persistence on a Windows computer, allowing it to remain active after a reboot. It has also been observed adding exclusions to Microsoft Defender in an attempt to avoid detection.
Extensive surveillance capabilities
CHOSEN BRICK provides attackers with a range of surveillance capabilities.
The NCSC says the malware can collect contacts, emails and social media messages. It can also capture screen content and access the device’s microphone, potentially giving attackers visibility into both the victim’s communications and activities.
The information gathered can potentially be used to establish details about a target’s contacts, movements and daily activities.
The NCSC also warns that personal information belonging to some previous victims has appeared on pro-Iranian leak sites, potentially increasing the physical safety risks faced by those individuals.
The US Federal Bureau of Investigation tracks the malware family under the name HEAVYGRAM and has attributed its use to Iran’s Ministry of Intelligence and Security. The FBI has said the wider campaign dates back to at least 2023, while the NCSC’s advisory identifies CHOSEN BRICK activity from at least 2025.
International warning
The latest warning was issued jointly by the NCSC, the FBI and the Netherlands’ General Intelligence and Security Service (AIVD).
The agencies say the activity demonstrates how cyber operations can form part of wider efforts to monitor and suppress people considered opponents of the Iranian regime.
Paul Chichester, NCSC Director of Operations, said the campaign demonstrated Iran’s use of digital surveillance against critics of the regime and urged people who may be at risk to familiarise themselves with the techniques being used.
The NCSC has published technical indicators and mitigation advice for organisations and individuals concerned that they may have been targeted.
The warning highlights the increasing importance of treating unexpected messages and files with caution, particularly when they arrive through personal messaging services and appear to come from trusted contacts.
For high-risk individuals, the agencies recommend paying particular attention to unsolicited requests to download software or open files, keeping operating systems and security software up to date, and investigating suspected compromises with appropriate technical support.
The campaign also demonstrates how attackers can combine detailed research about a target with convincing social engineering. Rather than relying solely on a generic phishing email, the Iranian actors are reported to tailor their approach around information they have gathered about individual victims.
The NCSC’s advisory provides further technical information about CHOSEN BRICK, its attack chain and indicators of compromise for organisations seeking to investigate potential infections.

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
