Security News

Iranian State Hackers Deploy 'Chosen Brick' Malware via Fake Apps on WhatsApp and Telegram

The Register · 16 Sept 2026
Key Takeaway Be cautious of unsolicited files or app links sent via messaging platforms, even from apparently trusted contacts, and verify before downloading anything unexpected.

The FBI, UK National Cyber Security Centre, and the Netherlands' AIVD have jointly warned that Iranian state cyber actors are targeting individuals through WhatsApp and Telegram to install surveillance malware known as Chosen Brick on Windows devices. Active since at least 2025, the malware steals contacts, emails, and social media messages, allowing operators to track victims' movements and activities.

Attackers conduct extensive research on targets before making contact, often impersonating trusted contacts or organisations to build rapport. They then persuade victims to download and open a malicious file disguised as legitimate software such as Norton Antivirus, Telegram, Adobe Flash Player, KeePass, Pictory, or RunwayML. Once opened, the malware runs silently, survives a system reboot, and adds exclusions to Microsoft Defender to avoid detection. It then communicates with attackers through a victim-specific Telegram bot.

The advisory noted that while Chosen Brick has not yet been observed spreading automatically across networks, doing so is technically feasible. Authorities linked this activity to Iran's broader pattern of targeting dissidents, activists, and journalists perceived as threats to the regime.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.