UK, US and Netherlands expose CHOSEN BRICK spyware
GCHQ's NCSC, with US and Dutch partners, warned that Iranian state actors use CHOSEN BRICK against dissidents, activists and journalists. Al Jazeera says the FBI attributed the malware to Iran's Ministry of Intelligence and Security. The Register adds that observed implants hit Windows only, arriving through WhatsApp and Telegram, and using Telegram bots for command.
Geopolitics··Morning
NCSC says the family steals mail and can open a microphone
GCHQ's National Cyber Security Centre said Iranian state cyber actors trick targets into downloading software that can track them. The spyware family dubbed CHOSEN BRICK collects contacts, emails and social media messages and can capture screen content and access a device microphone. Partners include US and Netherlands agencies. Dissidents, activists and journalists, including in the UK, are among those targeted. The alert is dated 15 September 2026.[2]
The FBI names MOIS; lures include fake MRI scans
Paul Chichester, director of operations at Britain's NCSC, said the campaign stole emails and messages in pursuit of repressing critics of the Iranian government. The FBI attributed the malware to Iran's Ministry of Intelligence and Security (MOIS) and said it was used to collect intelligence, conduct data leaks and inflict reputational harm. The joint advisory said operators first built rapport on messaging apps, then had targets open files dressed as apps such as Pictory or Telegram, or as MRI results. Personal details of some victims later appeared on leak sites.[1]
Observed cases stay on Windows after reboot
Jessica Lyons, writing Tuesday 15 September 2026, says the FBI, UK NCSC and Dutch AIVD warned that Iranian state cyber actors use messaging apps to drop surveillance malware on Windows machines. In all observed cases the malware infected Windows only, and Iran has used it since at least 2025. Attacks typically begin with WhatsApp and Telegram messages that appear to come from known contacts. The malware survives reboot, adds Microsoft Defender exclusions, and connects to Telegram for command and control with a victim-specific bot. NCSC lists the family's microphone and screen abilities; The Register adds the Windows-only observation and Telegram command. Al Jazeera's FBI-MOIS attribution sits on the same Tuesday advisory.[3], [2], [1]