NCSC, FBI and AIVD warn about CHOSEN BRICK spyware targeting dissidents and journalists
British, U.S. and Dutch security agencies released technical details about the Windows spyware CHOSEN BRICK, which they say was used by actors operating on behalf of Iran’s MOIS.

CHOSEN BRICK spyware is the subject of a joint warning from the United Kingdom’s National Cyber Security Centre (NCSC), the U.S. FBI and the Dutch intelligence service AIVD. On September 15, 2026, the agencies said the campaign targeted dissidents, activists and journalists, including people in the United Kingdom, the U.S. and the Netherlands.
NCSC calls the malware CHOSEN BRICK, while the FBI uses the name HEAVYGRAM. The FBI attributes its deployment to actors operating on behalf of Iran’s Ministry of Intelligence, MOIS. However, this is an assessment by security and intelligence agencies, not an independently publicly verified judicial finding.
CHOSEN BRICK spyware spreads through messages and attachments
According to the published advisories, attackers use social engineering through Telegram, WhatsApp and other social platforms. They persuade victims to run a file presented as a legitimate application or document. The FBI says this approach has already led to successful malware delivery and victim infections.
Publicly described samples have been observed exclusively on Windows. After execution, the malware may establish persistence after a device restart, add exclusions to Microsoft Defender, and use Telegram bots for control and communication.
The published technical materials attribute extensive data-collection capabilities to the malware:
- screen capture,
- audio recording through the microphone,
- theft of email and browser data,
- collection of data from Telegram and WhatsApp.
NCSC warns that data from some earlier victims appeared on pro-Iranian leak websites. In a compromised device, this therefore concerns not only the contents of the computer itself, but also the user’s communications and contacts.
FBI publishes indicators of compromise
A significant part of the joint warning consists of technical information intended for network defenders. The FBI published indicators of compromise and detection signatures, while NCSC describes the infection chain, persistence and communication mechanisms. Based on the available materials, organizations can search logs and endpoint devices for traces of the campaign.
The notice does not concern a security fix for a specific vulnerability. The described attack method relies primarily on persuading users to open or run a malicious file themselves. NCSC therefore recommends not installing software from links and attachments delivered in messages, keeping devices updated, and not ignoring SmartScreen warnings.
Different timelines for the CHOSEN BRICK and HEAVYGRAM designations
Some uncertainty remains in the materials regarding the malware family’s timeline and naming. NCSC says CHOSEN BRICK has been used since at least 2025. The FBI, by contrast, writes that related HEAVYGRAM samples were used from fall 2023. Public documents do not fully explain whether these dates describe different phases of the same malware family.
Further developments will also depend on whether the three agencies add new indicators of compromise, samples or information about the extent of affected individuals. AIVD said that Dutch victims had been informed. No public response from Iranian authorities or further independent confirmation of the attribution to MOIS has been announced.
Sources
- UK National Cyber Security Centre – The joint technical warning describes the infection chain, CHOSEN BRICK’s capabilities, Windows persistence, Telegram C2, indicators and recommended mitigations.
- FBI Internet Crime Complaint Center – The FBI technical analysis calls the malware HEAVYGRAM and provides its assessment of the link to MOIS, successful victim infections, samples and additional IoCs.
- Algemene Inlichtingen- en Veiligheidsdienst – The Dutch AIVD confirms the joint warning, says Dutch victims were informed, and describes the targeting of critics of the Iranian regime.
- SecurityWeek – Secondary reporting that highlighted the release of the joint warning and the FBI’s technical analysis.
Verified and updated: 09/16/2026 15:26



