SOCLYDE logo
Current languageEN
Cybersecurity newsMalwareEspionageWindows

Chosen brick: windows spyware turns trusted conversations into surveillance

The NCSC–FBI–AIVD alert details CHOSEN BRICK, Windows malware used against dissidents, activists and journalists, and the checks to perform after exposure.

By Soclyde Team

Person isolating a Windows computer after a suspicious message

In summary

  • The joint alert published on September 15, 2026 describes a campaign mainly targeting dissidents, activists and journalists perceived as hostile to the Iranian regime.
  • CHOSEN BRICK arrives through social engineering, poses as legitimate software or a document, then persists through a Windows Run key and communicates with a dedicated Telegram bot.
  • After a suspicious file is opened, isolate the device, have the indicators of compromise investigated and change exposed secrets from a clean device.

Explore next

Soclyde resources

Article contents

On September 15, 2026, the UK National Cyber Security Centre, the FBI and the Dutch AIVD published a joint advisory on CHOSEN BRICK, a Windows malware family attributed to Iranian state cyber actors. The alert describes targets in several countries, including dissidents, activists and journalists, with activity observed since at least 2025.

The issue is not limited to installing malware. The attackers first build a credible relationship through WhatsApp or Telegram, then use fake software or a fake document to take control of the device and access communications, accounts and the target’s daily patterns.

What the advisory establishes

The agencies do not describe a randomly distributed Windows campaign. They report targeting people perceived as critics of the Iranian regime, along with possible publication of some victims’ personal details on pro-Iranian leak sites. That exposure can increase harassment and, for people already at risk, the danger to their physical safety.

CHOSEN BRICK has been observed exclusively on Windows. The FBI tracks the same family under the name HEAVYGRAM in its technical analysis. The naming difference does not change the mechanism described: a file that looks legitimate triggers the installation of a component that can control the device in the background.

Fake software is the entry point

The chain starts with a conversation on a messaging platform. The operator may pose as someone the target knows or as platform technical support, after researching the target. The resulting trust makes downloading a file feel like a normal next step.

The documented lures imitate known applications such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass. Other files look like MRI results. Once opened, the file displays a screen consistent with the pretext so the target is less likely to notice, while downloading and executing CHOSEN BRICK in the background.

The actors often begin with a work or corporate computer. If the organisation’s controls block the file or make detection likely, they may ask the person to open it on a personal device instead. The boundary between workplace security and the individual’s security therefore becomes part of the defence.

Persistence, collection and exfiltration

CHOSEN BRICK survives a reboot by adding an entry to HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run. That key runs when the user logs in and does not require administrator privileges. The malware can also add exclusions to Microsoft Defender so selected files avoid scanning.

Once active, each device communicates with its own Telegram bot identifier. Collected data and files may leave through that channel or through object-storage services such as VultrObjects and StorjShare. Recent variants also use HTTPS or SOCKS5 proxies to make Telegram traffic harder to identify.

The advisory says automated lateral movement has not been observed. CHOSEN BRICK can nevertheless download additional payloads and give them similar persistence. It is important to separate what has been observed from what remains technically possible.

What can leave the device

Documented commands include listing processes and system information, capturing the screen, enabling the microphone, copying Telegram and WhatsApp data available through browsers, and stealing email content. The malware can also download files, delete files and, in at least one sample, wipe the system.

A screenshot does not reveal only the window currently open. It can expose a person’s contacts, location or daily routine. The agencies say personal information from some victims has subsequently been published. For a journalist, activist or dissident, the risk therefore includes colleagues and sources, not only the infected computer.

What to do after opening a suspicious file

On the potentially compromised computer, interrupt network access and avoid continuing to use accounts. Do not immediately delete the file, logs or disk: investigators need the evidence that can confirm what happened. Involve your IT team or a specialist incident-response provider.

From a clean device, change passwords for accounts used on the computer, starting with the primary email and recovery accounts. Revoke sessions, rotate keys or tokens where applicable and enable phishing-resistant MFA. If the file was opened on a personal computer, treat personal accounts and messages with the same urgency.

Do not download software sent through a link or attachment, even when the conversation feels familiar. Use the official site entered manually, keep Windows and applications up to date, keep antivirus enabled and do not disable SmartScreen warnings to make a file run.

What organisations should check

An organisation concerned about execution should search available logs and affected devices for the indicators in the joint advisory. SMQDService and winappx entries in the Run key, along with the unusual C:\Windows \SysWOW64 path, are documented examples rather than a complete list of names to block.

Network monitoring should also review unexpected connections to api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com and lightningproxies.net. These domains can be legitimate or shared by other uses, so their presence alone does not prove an infection. The combination of a device, timing and unusual behaviour is what warrants investigation.

Teams should also brief people who may be targeted, including when they use personal devices. Phishing-resistant MFA, application allowlisting, managed antivirus, endpoint logging and the ability to revoke access quickly all reduce the impact of a file opened by mistake.

The Soclyde connection

Soclyde does not protect the people targeted by CHOSEN BRICK and cannot replace device investigation or incident response. Its role is before and after an incident: generate a different secret for each service, keep those secrets in an encrypted vault and make rotation more practical when an account or session must be revoked.

Takeaway

CHOSEN BRICK shows how trust in a conversation can come before malware. The file may look like a familiar tool or an expected document, then establish Windows persistence, collect communications and exfiltrate data. For people at risk, the priority is never installing software from a message and having any device that opened a lure investigated.

For a practical next step, read our infostealer risk guide or contact Soclyde.

Frequently asked questions

Does CHOSEN BRICK target every Windows user?

No. The agencies describe targeted operations against people considered threats by Iran, including dissidents, activists and journalists. That does not make fake software harmless to other users, but the alert does not describe indiscriminate distribution.

What signs may indicate a compromise?

Priority checks include the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, entries such as SMQDService or winappx, the unusual C:\Windows \SysWOW64 directory and unexpected connections to services such as api.telegram.org, vultrobjects.com or storjshare.io. These are not exclusive indicators: names can change.

What should I do after opening fake software?

Disconnect the device from the network without deleting evidence needed for analysis, notify your IT team or a specialist, then change secrets used on the device from a clean one. Revoke active sessions and include personal accounts if the file was opened on a private device.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading