A Fake Antivirus Installer Did the Damage
The UK's National Cyber Security Centre, the US Federal Bureau of Investigation, and the Netherlands' AIVD intelligence service published a joint advisory on September 15, 2026, attributing a Windows spyware family called CHOSEN BRICK to Iranian state-linked actors. The FBI said Iran's Ministry of Intelligence and Security uses the malware to collect intelligence, conduct data leaks, and inflict reputational harm on its targets. NCSC Director of Operations Paul Chichester said Iran ruthlessly uses digital surveillance to repress critics of the regime, stealing emails and messages and accessing devices.
The delivery method is what makes this case worth reading past the headline. Operators opened contact with targets on WhatsApp or Telegram posing as someone the target knew, built rapport over several days, then delivered the malware hidden inside files disguised as familiar, trusted software: Norton Antivirus, Adobe Flash Player, the password manager KeePass, Telegram itself, and the AI tools Pictory and RunwayML. A target expecting to install protection software installed surveillance software instead.
Why It Matters: A Brand Name Was the Attack Surface
Security awareness training routinely tells people to trust known, reputable software names and be suspicious of unfamiliar ones. This campaign inverts that instinct directly: it uses the reputations of Norton Antivirus and KeePass, two names people are trained to trust precisely because they are security tools, as the disguise. A user who checks that a download is named after a well-known antivirus product or password manager is doing exactly the check this campaign was built to pass.
The lesson is not that security software is untrustworthy. It is that a familiar filename or icon is not verification, and that the WhatsApp or Telegram message building rapport before the file arrives is the actual moment worth training people to notice, not the file itself.
What the Malware Actually Does
Once running, CHOSEN BRICK harvests the victim's contacts, email inbox, and social media messages, captures screen content, and can activate the device microphone, according to the joint advisory and independent technical reporting. It survives a reboot through a persistence entry under the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, a detail specific enough for any Windows-focused security team to check its own endpoints against. The campaign is Windows-only and has targeted dissidents, activists and journalists in the UK, US and Netherlands since at least 2025.
The three agencies frame the disclosure as a joint attribution rather than a single-country finding, which is itself notable: the same indicators are now public and actionable across three national cybersecurity authorities at once, rather than surfacing piecemeal in separate national advisories months apart.
What This Means for Any Organization's Security Training
The advisory names its intended targets as dissidents, activists and journalists, not businesses, but the delivery tradecraft, days of rapport-building on a messaging app followed by a file disguised as trusted software, is generic and already shows up in corporate spearphishing and business email compromise. Any organization whose staff include journalists, NGO workers, or executives with a public profile connected to a diaspora or advocacy community should treat this advisory's indicators, including the specific registry persistence key, as something to check for directly rather than filing the story under human rights news and moving on.
Read next: Claude Became A Weapons Engineering Team | Ramp AI Usage Fast, and No One Has to Say Why It Slows



