The UK’s National Cyber Security Centre, the FBI, and the Dutch General Intelligence and Security Service (AIVD) published a joint advisory this month exposing a Windows spyware campaign run by Iran’s Ministry of Intelligence and Security. The NCSC tracks the malware family as CHOSEN BRICK. The FBI tracks the same tooling under a separate internal name, HEAVYGRAM. Both labels describe the same operation: a social-engineering-driven spyware campaign aimed at dissidents, activists, journalists, and human rights defenders in the UK, the US, the Netherlands, and other countries.
The advisory is notable less for the malware’s sophistication and more for how it gets onto a victim’s machine in the first place. Operators pose as trusted contacts on WhatsApp and Telegram, then talk targets into opening what looks like an ordinary file: a password manager, a video creation tool, or a set of MRI scan results. Once opened, the file drops a Windows payload that gives Iranian operators a foothold on the target’s system. The NCSC’s advisory has already been picked up by Infosecurity Magazine, Al Jazeera, and other outlets around the world.
What Is CHOSEN BRICK, and Why the FBI Calls It HEAVYGRAM
CHOSEN BRICK is the name the NCSC assigned to the spyware family in its advisory. The FBI’s parallel designation, HEAVYGRAM, refers to the same malicious code observed in US-based investigations. Two agencies tracking one operation under two names is routine in threat intelligence: NCSC and FBI research teams frequently develop their own internal naming conventions before comparing notes, and joint advisories like this one are usually the first place the public sees both names tied together.
What matters more than the naming is the platform. According to the advisory, CHOSEN BRICK infects Windows systems only. That’s a deliberate scope decision on the part of the operators, not a technical limitation of Iranian tooling in general. Windows still dominates the desktop and laptop base that journalists, researchers, and NGO staff use for day-to-day work, which makes it the highest-yield target for a campaign built around document-based lures rather than expensive zero-click exploits.
Who’s Behind It: Iran’s Ministry of Intelligence and Security
The three agencies attribute the campaign to Iran’s Ministry of Intelligence and Security, commonly abbreviated MOIS. MOIS is Iran’s primary civilian intelligence service, distinct from the Islamic Revolutionary Guard Corps, and has been named in prior Western government advisories covering surveillance of dissidents abroad. This advisory does not stand alone. It sits inside a pattern of NCSC, FBI, and allied publications that track Iranian state-linked cyber activity, several of which CISA catalogs under its dedicated Iran nation-state actor publications page.
Attribution in cases like this comes from a mix of infrastructure analysis, malware code overlap with previously tracked tooling, and victim targeting patterns, methods the three agencies describe only in general terms in the public version of the advisory. The technical detail supporting the MOIS attribution sits in the full NCSC advisory document, released alongside the announcement, rather than in summary press coverage.
Inside the Joint NCSC, FBI, and AIVD Advisory
Joint advisories across three national agencies don’t happen for minor campaigns. The NCSC, FBI, and AIVD coordinated timing and content before publication, a process that typically takes weeks of cross-agency review to align technical findings and legal sign-off across three separate government systems. The table below summarizes what the advisory confirms.
| Attribute | Detail |
|---|---|
| NCSC tracking name | CHOSEN BRICK |
| FBI tracking name | HEAVYGRAM |
| Attributed to | Iran’s Ministry of Intelligence and Security (MOIS) |
| Advisory issued by | NCSC (UK), FBI (US), AIVD (Netherlands) |
| Platform targeted | Windows only |
| Primary delivery channels | WhatsApp, Telegram |
| Confirmed targets | Dissidents, activists, journalists, human rights defenders |
| Countries with confirmed targets | UK, US, Netherlands, and other countries |
| Command-and-control channel | Telegram bots, one per victim |
| Exfiltration path | Telegram bot plus commodity cloud storage services |
The most operationally significant line in that table is the last one. Routing stolen data through mainstream cloud storage providers, rather than bespoke servers Iranian operators control directly, makes the exfiltration traffic harder to flag. Analysts looking at outbound connections see traffic to a well-known cloud provider instead of an obviously suspicious IP address, which buys the campaign time before defenders notice anything is wrong.
How CHOSEN BRICK Gets Onto a Target’s Machine
There’s no exploit chain here in the traditional sense. The advisory describes a social engineering approach: operators impersonate people the target already trusts, then send a file through WhatsApp or Telegram designed to look legitimate. The victim opens what they believe is a normal document or application, and the Windows payload installs quietly in the background.
Windows-Only, By Design
Building malware for a single platform cuts development cost and lets operators focus their engineering effort on making the payload harder to detect on the systems that matter most to them, rather than spreading resources across macOS or mobile variants. For a campaign that has reportedly run since at least 2023, according to the joint investigations referenced in the advisory, that kind of platform focus suggests operators prioritized stability and evasion over breadth.
The Lures: Fake Apps, Fake Documents, Real Deception
The advisory names three specific lures operators have used to disguise the CHOSEN BRICK payload: a video creation tool called Pictory, the open-source password manager KeePass, and fake MRI scan results. The medical document angle is worth sitting with for a moment. Sending someone a set of scan results plays on urgency and personal concern in a way a generic attachment doesn’t, and it’s the kind of file a target might open on a personal device without thinking twice, especially if the sender appears to be someone they know.
| Lure | Disguised as | Delivery channel |
|---|---|---|
| Pictory impersonation | Video creation software | WhatsApp / Telegram |
| KeePass impersonation | Password manager application | WhatsApp / Telegram |
| Fake MRI scan results | Personal medical document | WhatsApp / Telegram |
None of the three lures require the target to visit a malicious website or click a link buried in an email. Everything arrives inside a messaging app the target already uses daily, sent by an account that has taken time to build a plausible identity. That’s a slower, more labor-intensive approach than mass phishing, and it points to a campaign built around a relatively small number of high-value targets rather than broad, indiscriminate spraying.
Command and Control: One Telegram Bot Per Victim
Once installed, CHOSEN BRICK communicates back to its operators through Telegram bots, and the advisory specifies that each victim gets a separate bot identity. That’s a deliberate operational security choice. If defenders identify and report one bot, only one victim’s channel goes dark. The rest of the campaign keeps running untouched, which limits the blast radius of any single detection and makes wholesale takedown far harder for platform trust-and-safety teams.
The advisory also notes that newer versions of the malware route traffic through proxies before it reaches the Telegram infrastructure, adding another layer between the victim’s machine and whoever is reading the stolen data on the other end. Combined with cloud storage for the bulk data exfiltration itself, the design shows operators iterating on evasion rather than standing still, which is consistent with a campaign that has had roughly three years to mature.
Who Iran Is Targeting, and Where
The advisory names four categories of targets: dissidents, activists, journalists, and human rights defenders. Confirmed targeting has been reported in the UK, the US, and the Netherlands, with the agencies noting activity in other parts of the world as well without naming every country involved. That geographic spread lines up with where the Iranian diaspora and exiled opposition figures tend to concentrate, rather than pointing to any single national security target.
This is a pattern that outside observers, including independent security analysts, have connected to Iran’s long-running discomfort with critical coverage and organizing efforts based outside its borders. People who left Iran and continue to speak publicly, or who report on the country from abroad, remain within reach through their phones and laptops even after they’ve physically left.
Historical Context: Iran’s Long Run of Cyber Espionage
CHOSEN BRICK doesn’t appear out of nowhere. Security researchers have tracked Iran-linked threat groups going after journalists and dissidents for close to a decade, under a rotating set of industry names that differ from vendor to vendor. What’s changed over that period isn’t Iran’s interest in this target set so much as the delivery method: earlier campaigns leaned more heavily on spearphishing email and fake login pages, while the shift toward WhatsApp and Telegram tracks the same shift in how people actually communicate day to day.
Commercial spyware has followed a similar arc across different countries entirely. The 2021 Pegasus Project investigation, led by Forbidden Stories with support from Amnesty International’s Security Lab, publicly tied Israeli firm NSO Group’s Pegasus tool to surveillance of journalists and activists through a leaked list of tens of thousands of phone numbers. In 2024, the US Treasury’s Office of Foreign Assets Control sanctioned the Intellexa Consortium, the group behind the Predator spyware, over similar concerns. CHOSEN BRICK fits into that broader story: state and state-adjacent actors increasingly see the phones and laptops of dissidents as legitimate intelligence targets, regardless of which government is doing the targeting.
How CHOSEN BRICK Compares to Other State-Sponsored Spyware
The comparison that jumps out immediately is against tools like Pegasus. NSO Group built its reputation on zero-click exploits that require no action from the target at all, which is a far more technically expensive approach than anything described in the CHOSEN BRICK advisory. CHOSEN BRICK instead leans entirely on convincing a human being to open a file, a cheaper and more accessible method that doesn’t require the kind of exploit development budget a zero-click chain demands.
That trade-off cuts both ways. Zero-click tools work regardless of how careful a target is, but they burn expensive exploits that get patched once discovered. Social-engineering-driven campaigns like CHOSEN BRICK are cheaper to run and easier to replace when caught, but they depend on the target’s judgment in the moment, which means basic user awareness training and a habit of verifying unexpected files before opening them meaningfully reduce the odds of a successful compromise. For organizations advising at-risk staff, that difference should shape where security budget goes: fewer resources spent chasing hypothetical zero-days, more spent on training people to pause before opening an unexpected file from a “trusted” contact.
Industry and Market Impact
Joint advisories like this one tend to ripple through the security industry in predictable ways. Endpoint detection vendors typically update signatures and behavioral rules within days of a public advisory naming a new malware family, and NGOs that work with at-risk populations, from press freedom groups to human rights organizations, often use these advisories as the trigger to refresh their own digital security guidance for staff and sources.
There’s also a reputational dimension for the messaging platforms named in the advisory. WhatsApp and Telegram have both faced scrutiny before over how state-linked actors abuse their platforms for targeting, and each fresh advisory naming them as a delivery channel adds pressure on their trust-and-safety teams to tighten detection of impersonation accounts and bot-based command infrastructure, even when the platform itself isn’t compromised and the abuse is happening entirely at the social engineering layer.
What Organizations and At-Risk Individuals Should Do Now
The advisory’s practical guidance boils down to a few habits that cost nothing and take minutes to build into a routine. None of this requires specialized tools, just a change in how unexpected files get treated before they’re opened.
Before opening any unexpected file sent over WhatsApp or Telegram:
1. Verify the sender through a second channel (phone call, in-person, separate app)
2. Treat "urgent" or personal-sounding attachments (medical results, legal documents) with extra suspicion
3. Do not run installers for common software (password managers, editing tools) received via chat
4. Check the file extension carefully -- executables disguised as documents are the core of this campaign
5. Report suspicious contacts and files to your organization's security team or a digital security helpline
6. Keep Windows and endpoint protection fully patched and updated
For Journalists and Activists
People who fall into the target categories named in the advisory, dissidents, activists, journalists, and human rights defenders, should treat any unsolicited file from a contact claiming urgency as a red flag first and a legitimate request second. Several press freedom and digital rights organizations offer free digital security consultations specifically for this kind of threat model, and the advisory itself is a reasonable prompt to reach out to one if you haven’t already.
For Security Teams
Security teams at NGOs, newsrooms, and advocacy organizations should treat this advisory as a prompt to review outbound traffic monitoring for connections to commodity cloud storage from endpoints that have no legitimate business reason to use them, and to brief at-risk staff directly rather than relying on a general company-wide security memo that’s easy to skim past.
What Comes Next: 5 Predictions
- Expect endpoint security vendors to publish detection signatures referencing both the CHOSEN BRICK and HEAVYGRAM names within the coming weeks, since dual naming from two agencies tends to get folded into vendor threat feeds quickly to avoid confusion.
- Expect at least one more government or allied agency, beyond the UK, US, and Netherlands, to publicly confirm CHOSEN BRICK activity against its own nationals or residents, given the advisory’s note that targeting extends to other parts of the world.
- Expect WhatsApp and Telegram to face renewed questions from journalists and lawmakers about platform-level defenses against bot-based command infrastructure, even though the compromise itself happens outside the platforms’ own systems.
- Expect Iranian state-linked operators to iterate on the lure set once CHOSEN BRICK’s current disguises, Pictory, KeePass, and fake MRI results, become widely recognized, since publicity typically forces a campaign to retool its social engineering angle.
- Expect digital security trainers working with journalists and activists to fold this advisory directly into existing training material, given how closely the delivery method matches threat models these groups already prepare for.
Frequently Asked Questions
What is CHOSEN BRICK spyware?
CHOSEN BRICK is the NCSC’s tracking name for a Windows spyware family that a joint advisory from the NCSC, FBI, and AIVD attributes to Iran’s Ministry of Intelligence and Security. It targets dissidents, activists, journalists, and human rights defenders through fake files sent over WhatsApp and Telegram.
Is CHOSEN BRICK the same as HEAVYGRAM?
Yes. HEAVYGRAM is the FBI’s internal tracking name for the same malware family the NCSC calls CHOSEN BRICK. Both names refer to the same campaign described in the joint advisory.
Who is behind the CHOSEN BRICK campaign?
The NCSC, FBI, and AIVD attribute the campaign to Iran’s Ministry of Intelligence and Security (MOIS).
Which operating system does CHOSEN BRICK infect?
According to the advisory, CHOSEN BRICK infects Windows systems only.
How is CHOSEN BRICK delivered to targets?
Operators use WhatsApp and Telegram to contact targets while impersonating trusted individuals, then send disguised files, including fake versions of the Pictory video tool, the KeePass password manager, and fake MRI scan results, to trick targets into installing the malware.
Which countries have confirmed CHOSEN BRICK targets?
The advisory confirms targeting in the UK, the US, and the Netherlands, with additional activity reported in other parts of the world.
How does CHOSEN BRICK communicate with its operators?
The malware uses Telegram bots for command and control, with a separate bot identity assigned to each victim, and exfiltrates stolen files through the Telegram bot and commodity cloud storage services.
What should I do if I think I’ve been targeted?
Do not open the suspicious file. Verify the sender through a separate communication channel, disconnect the affected device from the network if you already opened something suspicious, and contact your organization’s security team or a digital security helpline for journalists and activists.




