Breaking NewsUpdated as information becomes available
News·Threat Intelligence·20 September 2026·Breaking

NCSC exposes Iranian spyware targeting dissidents, activists and journalists

The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
6 min read
Share
A journalist at a Windows laptop facing a targeted surveillance threat, with physically disconnected secure storage in the foreground
A journalist at a Windows laptop facing a targeted surveillance threat, with physically disconnected secure storage in the foreground

Why it matters

What this means for organisations holding critical data

The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.

The UK National Cyber Security Centre has joined the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service in exposing malware used by Iranian state cyber actors against dissidents, activists and journalists.

The joint advisory, published on 15 September 2026, names the malware family CHOSEN BRICK. The agencies say it has targeted people around the world, including in the United Kingdom, United States and Netherlands, since at least 2025.

This is not simply another information-stealing campaign. The NCSC says the malware can collect a target's contacts, emails and social media messages, information that could be used to track their movements. It assesses that Iran almost certainly uses cyber activity to support the repression of people viewed as threats to the regime.

The advisory adds a stark physical dimension. The NCSC says Iranian intelligence services have, in some cases, plotted kidnappings or lethal operations against people abroad whom they perceive as enemies. Personal details belonging to some previous CHOSEN BRICK victims have appeared on pro-Iranian leak sites, potentially increasing risks to their safety.

Trust is the first attack surface

The campaign begins with careful social engineering rather than a noisy technical exploit. According to the advisory, operators research their intended target and tailor the approach. They may contact a person through WhatsApp or Telegram while impersonating someone the victim knows, or pose as technical support for a trusted platform.

The files are designed to fit the conversation. The agencies observed fake versions of applications including Telegram, Norton Antivirus, KeePass, Pictory and RunwayML. One lure was presented as the result of an MRI scan. The objective is to make opening the file feel reasonable in the moment.

The malware has exclusively targeted Windows devices in the cases the agencies observed. Attackers may first approach a work or corporate machine, then try to move the conversation to a personal device if they believe workplace monitoring makes detection more likely. That shift matters because a personal computer may sit beyond an organisation's managed security controls while still holding access to the same people, sources and conversations.

What CHOSEN BRICK can do

Once installed, CHOSEN BRICK can establish persistence, weaken Microsoft Defender by adding antivirus exclusions and connect to Telegram for command and control. The NCSC says every victim device uses a unique Telegram Bot ID, an operational-security measure that helps separate one compromise from another.

The malware can capture the screen, exfiltrate data and download further payloads. The related NCSC release says it can reportedly access a device microphone. Information can be sent through Telegram or cloud object-storage services, while newer variants use proxy infrastructure to disguise Telegram traffic.

The agencies have not observed automated lateral movement across a network. That does not make the threat minor. Its focus is the person and the device that holds their relationships. A single carefully selected laptop may contain a journalist's sources, an activist's organising network, travel plans, private correspondence and the identities of people whose exposure carries a real-world consequence.

One sample also contained data-wiping capability. The potential outcome therefore spans surveillance, theft, further compromise and destruction.

The cyber incident and the safety incident are the same event

Most breach reporting treats names, emails and messages as units in a database. Here, the value of the information lies in what it reveals about people: whom they trust, where they may be, what they intend to publish and who else is connected to them.

For journalists, campaigners, researchers and organisations supporting dissidents, the security question is not only whether a file is encrypted. It is whether there is any standing route from an internet-connected account or endpoint to the retained archive.

Strong authentication, current software, endpoint monitoring and social-engineering awareness remain essential. The NCSC describes awareness training as the best defence against the initial approach and provides technical indicators and mitigations for individuals and network administrators in its full advisory.

Those controls reduce the likelihood of compromise. They cannot make every person infallible, and they cannot turn an always-connected archive into an offline one.

The Firevault view: reduce what a compromised device can reach

A targeted individual may need email, messaging and research tools online. Historical source material, contact archives, evidence, identity records and completed work do not all need to remain continuously reachable from the same device.

Offline Secure Storage® provides a separate control: dedicated hardware with no standing network path. Access is opened only after an authorised out-of-band request, for a defined period, and then closed again. When the storage is offline, malware on a laptop cannot browse it, copy it, encrypt it or silently use it to map a person's network.

This does not claim to stop CHOSEN BRICK reaching a connected Windows device. Nor does it replace the NCSC's mitigations. It limits the body of sensitive retained information available after an endpoint or account is compromised.

For people facing state-backed surveillance, that distinction is not theoretical. If connected data can reveal a source, contact or movement, keeping the definitive archive physically disconnected can help place a hard boundary between a cyber intrusion and its wider human consequences.

Practical actions for at-risk people and organisations

  • Read the joint NCSC, FBI and AIVD advisory and use its indicators when investigating a suspected compromise.
  • Treat unexpected support messages and tailored file-sharing approaches with suspicion, even when the sender appears familiar.
  • Verify unusual requests through a separate, known communication channel before opening a file or installing software.
  • Keep Windows, security tools and applications current, and investigate unexpected antivirus exclusions.
  • Separate high-risk browsing and messaging from the systems used to retain source archives and identity material.
  • Keep an offline copy of sensitive records and recovery data that no compromised endpoint can reach.
  • Seek specialist help if you believe the activity may form part of transnational repression or pose a risk to physical safety.

Sources

Firevault is not affiliated with or endorsed by the NCSC, FBI or AIVD. Attribution and intelligence assessments in this article are reported as stated by those agencies.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires