Desk live·
ForensicPost
Nation-state/Espionage/File 26-0916

UK, US and Dutch Agencies Named Iranian State Spyware Aimed at Dissidents and Journalists

The CHOSEN BRICK advisory of 15 September describes Windows malware delivered by rapport-building on WhatsApp and Telegram, harvesting messages, screenshots and microphone audio from people who criticise Tehran. Stolen data surfaced on pro-Iranian leak sites. No organisation was the target; people were.

Constructed geometry · not a chart of case data
TargetIranian dissidents, activists and journalists
ActorIranian state actors (government attribution)
D. Kennedy9 min readConfidence: high4 sources reviewed

On 15 September 2026 the UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD published a joint advisory on CHOSEN BRICK, spyware they attribute to Iranian state cyber actors and describe as in use since at least 2025 against Iranian dissidents, activists and journalists worldwide, including in the three countries. A companion FBI notice reportedly tracks the same malware as HEAVYGRAM and assesses it is likely used by actors working for the Ministry of Intelligence and Security.

The delivery is social, not technical. Operators impersonate trusted contacts on WhatsApp and Telegram, build a relationship over time and then send a lure: fabricated medical results, or fake installers for legitimate tools. The Windows implant harvests contacts, email, messaging data from browsers, screenshots, microphone audio and location, persists through the registry, evades Defender, and exfiltrates through Telegram bots and commercial object storage. The agencies link data stolen this way to material later posted on pro-Iranian leak sites.

A Government Attribution, With The Reason Stated

The corpus grades attribution by who makes it. This is three governments, in a signed advisory, naming a state. The evidence cited is the appearance of victims’ data on leak personas the agencies had already assessed as Iranian, and the FBI’s separate finding that some data posted by the Handala persona was obtained with this malware. NCSC operations director Paul Chichester’s statement framed the purpose plainly as repression of critics. The advisory offers free defensive services to high-risk individuals in the UK.

The Target Is A Person, And The Harm Is Physical

Most files in this section concern organisations: a telecom, a ministry, a plant. This one has no organisation in it. The victims are individuals whose contacts, conversations and locations were taken, and the advisory notes that Iranian services have plotted kidnappings and killings of perceived enemies abroad. The reissuance line the corpus draws at 26-0324 does not begin to describe the exposure. A journalist’s source list and an activist’s location are not fields that can be replaced.

What The Advisory Can Do

It publishes indicators and mitigations. It cannot patch the mechanism, which is trust in a contact who has spent weeks earning it, and it cannot reach the population it warns except through the channels the operators also use. The corpus filed at 26-0810 the limits of an advisory against operators out of reach; here the operators are a state, the victims are dispersed and the advisory is, by its own framing, mostly a warning.

How we reported this

Compiled from the NCSC announcement and advisory and contemporaneous reporting, listed below. The FBI page could not be fetched directly; the HEAVYGRAM alias, the MOIS assessment and the Handala link are from reporting of it and are marked as such. Victim counts are not published. Graded high on the government attribution. Corrections: corrections@forensicpost.com.

Sources
  1. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalistsNational Cyber Security Centre
  2. Advisory: Iranian Cyber Targeting of Dissidents, Activists, and JournalistsFBI
  3. NCSC and Allies Warn of Iranian Spyware CampaignInfosecurity Magazine
  4. Chosen Brick, Iran’s Surveillance MalwareSecurity Affairs
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary