The UK's National Cyber Security Centre told high-risk individuals and the NGOs that support them to hunt for CHOSEN BRICK malware on Windows laptops after publishing a joint advisory with the FBI and Dutch AIVD on Iranian spear-phishing that impersonates contacts on WhatsApp and Telegram.
What CHOSEN BRICK does
The malware family targets dissidents, activists, and journalists perceived as threats to the Iranian regime, including people based in Britain. Once installed, it harvests contacts, email, and messaging history to enable physical tracking. NCSC assesses Tehran uses cyber operations to reinforce domestic repression and has plotted kidnappings abroad against perceived enemies. Victim details have appeared on pro-Iranian leak sites, increasing safety risks beyond data theft.
How infections start
Attackers build rapport over encrypted chat before sending malicious links or files disguised as interviews, event invites, or solidarity messages. The advisory stresses the malware persists across reboots on Windows systems. macOS and mobile paths were not observed in the campaign, but NCSC still recommends hardening phones used for two-factor codes.
Mitigations NCSC lists
Organisations should circulate the advisory to staff likely to be targeted, run the published indicators through endpoint tools, and preserve forensic images if compromise is suspected. Individuals can enrol in NCSC's free cyber defence services for high-risk people, including protective DNS and takedown support. Reporting goes through report.ncsc.gov.uk, monitored continuously.
UK legal and media organisations
Newsrooms covering Iran protests and exile politics face the highest exposure. Law firms handling asylum cases should segregate client communications from general firm email to limit lateral movement if a paralegal laptop is compromised. Universities hosting diaspora speakers ought to brief IT helpdesks on the campaign before autumn term events.
Corporate spillover
While the campaign focuses on individuals, contractors with dual roles in advocacy and commercial consultancies could bridge malware into corporate networks. NCSC asks businesses to treat infections on personal devices used for work as reportable if customer data was accessible. The Information Commissioner's Office may become involved if personal data of UK citizens leaks via spyware exfiltration.
What to do today
Update Windows, run offline scans with reputable tools, rotate passwords from a clean device, and warn contacts you may have been impersonated. Avoid clicking fresh chat links even when the sender looks familiar—verify through a second channel. Persistence means reimaging may be safer than partial cleans.
Indicators and enterprise SOC playbooks
The advisory ships YARA rules and registry keys analysts can drop into SIEM content packs. Managed service providers serving charities should run hunts this week because Iranian actors reuse infrastructure across campaigns. NCSC emphasises that rebooting alone will not clear CHOSEN BRICK; cold imaging preserves evidence if victims pursue civil remedies or notify insurers covering cyber extortion.
Government travel guidance
Foreign Office travel notes for Iran already warn British nationals about surveillance; the spyware advisory extends that logic to diaspora activists in London and Manchester. Universities hosting Iranian studies seminars should brief moderators not to distribute unvetted links in chat rooms during hybrid events.
Legal support channels
Reporters Without Borders UK and Index on Censorship circulate NCSC guidance to members Monday morning. Solicitors handling international human rights cases should store sensitive briefs on encrypted drives isolated from email clients that received the phishing lure. Insurance policies vary on whether state-sponsored spyware cleanup counts as covered incident response—policyholders should notify brokers before wiping disks.
Longer-term deterrence
NCSC coordinates with the National Crime Agency on attribution but public advisories rarely name operators. Diplomatic expulsions may follow separate intelligence channels; defenders should focus on containment regardless of geopolitics. Patching and user education remain the only scalable defences while messaging apps stay end-to-end encrypted.
Device hygiene for freelancers
Journalists and translators working on Iran-related contracts should segregate work laptops from family WhatsApp Web sessions. NCSC's protective DNS for high-risk users blocks known command-and-control domains, but zero-day links may still slip through until vendors update filters. Enabling Microsoft Defender attack surface reduction rules on Windows 11 closes common script execution paths CHOSEN BRICK relies upon during initial install.
