Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

Iranian ‘Chosen Brick’ Malware Uses Telegram to Spy on Dissidents, Journalists, and Activists

UK, US and Dutch agencies warned that the state‑linked ‘Chosen Brick’ malware is being delivered through Telegram to harvest contacts, emails and social‑media messages from journalists, activists and other dissidents. The campaign illustrates the need for continuous monitoring and evidence‑ready incident response when targeted surveillance can translate into physical threats.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 securityaffairs.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Chosen Brick: Iranian Malware Uses Telegram to Spy on Dissidents, Journalists, and Activists

What Happened – The UK NCSC, the U.S. FBI, and the Dutch AIVD issued a joint advisory describing “Chosen Brick,” a Windows‑based malware family employed by Iranian intelligence services. Since 2025 the malware has been delivered through Telegram, harvesting contacts, emails and social‑media messages from targeted individuals worldwide.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring programs must surface malicious command‑and‑control traffic on consumer platforms (e.g., Telegram) before data exfiltration occurs.
  • Defensible audit evidence of detection, containment, and forensic analysis is essential when state‑sponsored actors turn a compromised laptop into a physical‑harassment vector.

Who Is Affected – Human‑rights journalists, political dissidents, NGOs and other civil‑society actors in the UK, US, the Netherlands and globally.

Recommended Actions

  • Integrate outbound‑traffic analytics for popular messaging apps into your security monitoring stack.
  • Conduct targeted phishing and malware‑awareness drills that simulate Telegram‑borne payloads.
  • Document incident‑response playbooks that cover evidence preservation for state‑actor investigations.

Source: Security Affairs

Technical Notes – The payload is a Windows executable delivered via malicious Telegram links; it extracts contacts, email archives and social‑media messages, then uploads them to Iranian command servers. No public CVE is associated. Source: same

📰 Original Source
https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →