UK, US and Dutch Agencies Warn of Spyware Delivered Through Chat Apps

Britain's National Cyber Security Centre, the US Federal Bureau of Investigation, and the Netherlands' General Intelligence and Security Service (AIVD) published a joint advisory on Sept. 15, 2026, on a Windows spyware family they call CHOSEN BRICK. The NCSC says Iranian state actors have been observed using it against dissidents, activists, and journalists around the world, including in the UK.
The advisory is aimed at organizations and at individuals who believe they may be targets, and is meant to help them spot the activity and reduce the chance of their devices falling victim to it.
The advisory says the malware has been aimed exclusively at the Windows operating system. It is persistent and will survive a reboot of the target device, and it can collect a target's contacts, emails, and social media messages, capture screen content, and reach the device's microphone.
Iranian state actors have been observed impersonating contacts over messaging apps such as WhatsApp and Telegram, building rapport with a target before deploying CHOSEN BRICK. They tailor their approach to areas their targets care about, in one case using fake MRI test results as a lure.
The NCSC says personal details of some earlier victims have appeared on pro-Iranian leak sites, potentially increasing the risk to their personal safety. It assesses that Iran almost certainly uses cyber activity to support the repression of individuals seen as a threat to the regime.
"With our international partners, we strongly encourage individuals at risk to familiarise themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice," said Paul Chichester, the NCSC's Director of Operations.
The FBI published a separate technical analysis of the malware on the same day.
