Skip to content
See the World Through ScienceA project of ALLATRA

UK, US and Dutch Agencies Warn of Spyware Delivered Through Chat Apps

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The J. Edgar Hoover Building, a long concrete office block in Washington, seen from a street corner under a clear sky.
The J. Edgar Hoover Building in Washington, headquarters of the FBI, one of the three agencies that signed the advisory (illustrative)."FBI Headquarters - J. Edgar Hoover Building (53840035941) b" by File:FBI Headquarters - J. Edgar Hoover Building (53840035941).jpg: ajay_suresh derivative work: Georgfotoart, via wikimedia, CC-BY-2.0 · CC-BY-2.0

Britain's National Cyber Security Centre, the US Federal Bureau of Investigation, and the Netherlands' General Intelligence and Security Service (AIVD) published a joint advisory on Sept. 15, 2026, on a Windows spyware family they call CHOSEN BRICK. The NCSC says Iranian state actors have been observed using it against dissidents, activists, and journalists around the world, including in the UK.

The advisory is aimed at organizations and at individuals who believe they may be targets, and is meant to help them spot the activity and reduce the chance of their devices falling victim to it.

The advisory says the malware has been aimed exclusively at the Windows operating system. It is persistent and will survive a reboot of the target device, and it can collect a target's contacts, emails, and social media messages, capture screen content, and reach the device's microphone.

Iranian state actors have been observed impersonating contacts over messaging apps such as WhatsApp and Telegram, building rapport with a target before deploying CHOSEN BRICK. They tailor their approach to areas their targets care about, in one case using fake MRI test results as a lure.

The NCSC says personal details of some earlier victims have appeared on pro-Iranian leak sites, potentially increasing the risk to their personal safety. It assesses that Iran almost certainly uses cyber activity to support the repression of individuals seen as a threat to the regime.

"With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice," said Paul Chichester, the NCSC's Director of Operations.

The FBI published a separate technical analysis of the malware on the same day.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

UK, US and Dutch Agencies Warn of Spyware Delivered Through Chat Apps

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.