As reported by SecurityAffairs, a joint advisory from the UK's NCSC, the FBI, and the Netherlands' AIVD has formally named Chosen Brick — a Windows malware family used by Iranian intelligence services to surveil dissidents, journalists, and activists since at least 2025. The advisory is significant not merely because it attributes a new malware strain, but because it draws an unusually direct line between a compromised endpoint and a credible physical threat to the person behind the keyboard.
What Makes This Advisory Different
Most nation-state malware disclosures land in the domain of espionage or industrial theft — serious, but bounded by data loss and competitive disadvantage. Chosen Brick sits in a different category. The advisory explicitly notes that Iranian intelligence services have plotted kidnapping and lethal operations against perceived opponents abroad, and that stolen data from Chosen Brick victims has surfaced on pro-Iranian leak sites as a harassment tool. This is surveillance that bleeds into kinetic action.
"A compromised laptop is normally a data problem. Here, it can become a physical safety problem for the person who owns it."
For defenders, that reframing matters. It changes the threat model from "what did we lose?" to "who is now in danger?" Incident response playbooks designed for data exfiltration are insufficient when the downstream consequence may be an attempt to locate, intimidate, or harm a human being.
The Telegram Attack Surface
The advisory confirms what researchers have tracked anecdotally since late 2023: Iranian actors continue to weaponize Telegram as both a delivery vector and command infrastructure. Telegram's ubiquity among the Iranian diaspora and dissident communities — precisely because it offers encrypted messaging and resists state censorship — makes it an ideal targeting channel. Threat actors impersonate trusted contacts, share malicious files masquerading as documents or media, and use Telegram bots for lightweight C2 that blends into legitimate traffic.
This is a social engineering problem at its core, not a technical one. The malware payload is Windows-native, but the initial access relies on trust, urgency, and platform familiarity — the same levers that drive every successful phishing operation.
Who Is at Risk
The contact-harvesting capability is particularly concerning. A single infected machine doesn't just compromise one person; it maps their entire network, enabling cascading targeting operations. Defenders should treat any confirmed Chosen Brick infection as a multi-victim event.
Broader Implications
This advisory continues a pattern of Western intelligence agencies becoming more willing to publicly attribute Iranian cyber operations and name specific tools. The joint format — spanning three jurisdictions — signals that the threat is not localized. Expect additional advisories as allied agencies consolidate threat intelligence on Iranian state cyber activity.
For organizations that support at-risk communities — NGOs, press freedom organizations, academic institutions with Iranian studies programs, diaspora associations — this is a wake-up call to treat endpoint security for personnel as a duty of care, not just an IT concern.
Shield53 Recommendations
- Threat-hunt for Telegram-based delivery: Review endpoint logs for suspicious Telegram downloads, unexpected executable or LNK files originating from Telegram client processes, and outbound connections to Telegram API endpoints from non-browser processes.
- Brief at-risk personnel: Deliver targeted security awareness training to individuals in affected categories. Focus on Telegram-specific lures: unsolicited file shares from unknown or newly created accounts, document attachments with executable extensions, and links claiming to lead to sensitive content.
- Deploy EDR with behavioral detection: Ensure endpoint detection rules cover Windows-side behaviors consistent with information-stealer and surveillance malware — contact enumeration, mail client database access, browser credential extraction, and communication with known suspicious infrastructure.
- Assume contact exposure: If an infection is confirmed, notify affected contacts that their information may have been compromised. Treat it as a data breach with human safety implications, not merely a device compromise.
- Harden high-risk individuals: Provide at-risk personnel with hardened devices, compartmentalized communication channels, and regular device resets. Consider dedicated burners for sensitive communications.
- Engage protective services when warranted: For individuals facing credible threats, coordinate with law enforcement protective details. The advisory explicitly links this malware to physical plots — treat that linkage seriously.
The international cybersecurity community has long treated state-sponsored surveillance malware through an intelligence-loss lens. Chosen Brick is a reminder that for some communities, the stakes are measured in personal safety, not data records. Defenders must adjust accordingly.