The UK National Cyber Security Centre, which is part of GCHQ, published a joint advisory on 15 September with the United States Federal Bureau of Investigation and the Netherlands’ General Intelligence and Security Service (AIVD) naming a Windows malware family called CHOSEN BRICK. The three agencies say Iranian state cyber actors have used it since at least 2025 to target dissidents, activists and journalists around the world, including people in the United Kingdom, the United States and the Netherlands, and the NCSC states that the malware lets operators collect a target’s contacts, emails and social media messages in a way that could allow their movements to be tracked (ncsc.gov.uk).

The technical portion of the advisory is unusually specific for a public document. It describes operators making contact through messaging platforms such as WhatsApp and Telegram while posing as trusted people, building rapport, and then persuading the target to open a file dressed up as something familiar. The advisory lists decoys imitating Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, and in some cases files presented as MRI scan results. Once installed, the malware persists through a reboot using the Run key under HKCU, adds exclusions to Microsoft Defender to avoid detection, and then reaches out to Telegram for command and control, with each compromised device assigned its own Telegram bot identifier so that victims cannot be linked to one another (ncsc.gov.uk).

The capability list reads like a surveillance kit rather than a criminal data grab. According to the advisory, operators can capture screen content, switch on the microphone to record audio, copy Telegram and WhatsApp data out of web browsers, steal email content, pull down further malware, and wipe the machine when they are finished (ncsc.gov.uk). The NCSC’s public summary confirms the malware has been aimed exclusively at Windows and that it survives a restart (ncsc.gov.uk). Cybersecurity and intelligence agencies in all three countries framed the release as an exposure of state surveillance tooling aimed at critics worldwide (securityweek.com).

Two passages carry the weight of the document. The agencies write that the personal details of some earlier CHOSEN BRICK victims have appeared on pro-Iranian leak sites, which they say potentially increases the risk to the personal safety of those affected. The advisory also states that Iran almost certainly uses cyber activity to support the repression of people seen as a threat to the regime, and that in some cases Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally (theregister.com).

Where the burden of defence actually falls

Having described a threat that can end in abduction or worse, the advisory hands most of the practical remedy back to the person being hunted. It says the best defence is for the user or victim to become more aware of social engineering through training, then lists steps such as avoiding software sent through attachments or links, keeping devices updated, running current antivirus software and not dismissing SmartScreen warnings. Organisations are told to enable phishing-resistant multi-factor authentication, deploy endpoint and network monitoring, search their logs for the published indicators, and circulate the advisory to staff who may be targeted so that personal devices get checked too (ncsc.gov.uk). That is sensible hygiene guidance, and it is also a long way from protection for a journalist whose address has already been posted on a leak site.

The speed of this attribution raises a fair question about consistency. Three governments identified the malware, the class of operator behind it and the category of victim, and they published indicators of compromise and detection signatures for anyone to use. Canada is not among the authoring agencies, and the advisory’s own list of affected countries covers the United Kingdom, the United States and the Netherlands (ncsc.gov.uk). Canadian diaspora communities face the same category of pressure from the same category of actor, so it is worth asking publicly what equivalent naming, notification and victim support exists here, and why comparable clarity is so much rarer when the surveillance tooling in question is commercial or domestic.

How the outlets framed it

SecurityWeek presented the release as agencies exposing a Windows malware family deployed against dissidents, activists and journalists worldwide, which keeps the human target in the first sentence while still reading as a security-industry bulletin. The Register’s coverage led with Iranian spies hitting Windows machines with data-stealing malware, a framing that foregrounds the machine and the theft, although the same piece carried the advisory’s line about plots to kidnap or kill people abroad. The NCSC’s own material puts repression first and describes victim details surfacing on pro-Iranian leak sites with a stated risk to personal safety. The difference matters because a story about transnational repression can quietly become a patching and indicator-of-compromise story, and the reader then never has to consider what a government owes the people it has just told are being hunted.

The indicators are public, the detection signatures are published, and the named malware will now be hunted across corporate networks. The people the advisory says are actually in danger are still expected to look after themselves.