Urgent.News

What's breaking now, across thousands of outlets.

Tech

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek .

US, UK, and Dutch government agencies have jointly reported on a malware campaign attributed to Iranian state cyber actors. The malware, known as Chosen Brick, is designed to infect Windows systems and steal sensitive information such as contacts, emails, and social media messages. According to the FBI, UK National Cyber Security Centre, and the Netherlands' General Intelligence and Security Service (AIVD), this malware has been used by Iran since at least 2025.

The attacks typically begin with social engineering campaigns via WhatsApp and Telegram, where the attackers pose as trusted individuals or organizations. The Iranian spies conduct extensive research on their targets, gathering knowledge of their contacts and relevant industry organizations before sending the initial message. The stolen data allows the attackers to track people's movements.

The security advisory noted that Iran uses cyber activity to support the repression of individuals perceived as threats to the regime, including dissidents, activists, and journalists. In some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally.

Brief written by urgent.news from SecurityWeek, The Register Science, The Register — 3 reports on this story. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at securityweek.com →

More in Tech

More from Wednesday 16 September →