On September 15, 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on CHOSEN BRICK, a Windows malware family attributed to Iranian state cyber actors. The alert describes targets in several countries, including dissidents, activists and journalists, with activity observed since at least 2025.
The issue is not limited to installing malware. The attackers first build a credible relationship through WhatsApp or Telegram, then use fake software or a fake document to take control of the device and access communications, accounts and the target’s daily patterns.
What the advisory establishes
The agencies do not describe a randomly distributed Windows campaign. They report targeting people perceived as critics of the Iranian regime, along with possible publication of some victims’ personal details on pro-Iranian leak sites. That exposure can increase harassment and, for people already at risk, the danger to their physical safety.
CHOSEN BRICK has been observed exclusively on Windows. The FBI tracks the same family under the name HEAVYGRAM in its technical analysis. The naming difference does not change the mechanism described: a file that looks legitimate triggers the installation of a component that can control the device in the background.
Fake software is the entry point
The chain starts with a conversation on a messaging platform. The operator may pose as someone the target knows or as platform technical support, after researching the target. The resulting trust makes downloading a file feel like a normal next step.
The documented lures imitate known applications such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass. Other files look like MRI results. Once opened, the file displays a screen consistent with the pretext so the target is less likely to notice, while downloading and executing CHOSEN BRICK in the background.
The actors often begin with a work or corporate computer. If the organisation’s controls block the file or make detection likely, they may ask the person to open it on a personal device instead. The boundary between workplace security and the individual’s security therefore becomes part of the defence.
Persistence, collection and exfiltration
CHOSEN BRICK survives a reboot by adding an entry to HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run. That key runs when the user logs in and does not require administrator privileges. The malware can also add exclusions to Microsoft Defender so selected files avoid scanning.
Once active, each device communicates with its own Telegram bot identifier. Collected data and files may leave through that channel or through object-storage services such as VultrObjects and StorjShare. Recent variants also use HTTPS or SOCKS5 proxies to make Telegram traffic harder to identify.
The advisory says automated lateral movement has not been observed. CHOSEN BRICK can nevertheless download additional payloads and give them similar persistence. It is important to separate what has been observed from what remains technically possible.
What can leave the device
Documented commands include listing processes and system information, capturing the screen, enabling the microphone, copying Telegram and WhatsApp data available through browsers, and stealing email content. The malware can also download files, delete files and, in at least one sample, wipe the system.
A screenshot does not reveal only the window currently open. It can expose a person’s contacts, location or daily routine. The agencies say personal information from some victims has subsequently been published. For a journalist, activist or dissident, the risk therefore includes colleagues and sources, not only the infected computer.
What to do after opening a suspicious file
On the potentially compromised computer, interrupt network access and avoid continuing to use accounts. Do not immediately delete the file, logs or disk: investigators need the evidence that can confirm what happened. Involve your IT team or a specialist incident-response provider.
From a clean device, change passwords for accounts used on the computer, starting with the primary email and recovery accounts. Revoke sessions, rotate keys or tokens where applicable and enable phishing-resistant MFA. If the file was opened on a personal computer, treat personal accounts and messages with the same urgency.
Do not download software sent through a link or attachment, even when the conversation feels familiar. Use the official site entered manually, keep Windows and applications up to date, keep antivirus enabled and do not disable SmartScreen warnings to make a file run.
What organisations should check
An organisation concerned about execution should search available logs and affected devices for the indicators in the joint advisory. SMQDService and winappx entries in the Run key, along with the unusual C:\Windows \SysWOW64 path, are documented examples rather than a complete list of names to block.
Network monitoring should also review unexpected connections to api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com and lightningproxies.net. These domains can be legitimate or shared by other uses, so their presence alone does not prove an infection. The combination of a device, timing and unusual behaviour is what warrants investigation.
Teams should also brief people who may be targeted, including when they use personal devices. Phishing-resistant MFA, application allowlisting, managed antivirus, endpoint logging and the ability to revoke access quickly all reduce the impact of a file opened by mistake.
The Soclyde connection
Soclyde does not protect the people targeted by CHOSEN BRICK and cannot replace device investigation or incident response. Its role is before and after an incident: generate a different secret for each service, keep those secrets in an encrypted vault and make rotation more practical when an account or session must be revoked.
Takeaway
CHOSEN BRICK shows how trust in a conversation can come before malware. The file may look like a familiar tool or an expected document, then establish Windows persistence, collect communications and exfiltrate data. For people at risk, the priority is never installing software from a message and having any device that opened a lure investigated.
For a practical next step, read our infostealer risk guide or contact Soclyde.


