Government cybersecurity agencies from the United States, United Kingdom, and Netherlands have jointly exposed a piece of Iranian state-sponsored surveillance malware known as Chosen Brick. The advisory, issued by the FBI alongside the UK's National Cyber Security Centre (NCSC) and the Dutch General Intelligence and Security Service (AIVD), warns that the malware is being actively used to spy on dissidents, journalists, and activists connected to Iran.

The joint disclosure marks a rare moment of coordinated public attribution against an Iranian intelligence operation, and it offers a window into how authoritarian governments extend surveillance well beyond their own borders.

What Is Chosen Brick and How It Operates

Chosen Brick, also referenced under the alias HEAVYGRAM in related research, is a Windows-based malware strain attributed to actors linked to Iran's Ministry of Intelligence and Security (MOIS). Rather than relying on broad, automated phishing sweeps, the campaign behind Chosen Brick appears to be built around targeted, personalized approaches to specific individuals the Iranian state considers threats.

According to the advisories, the malware has been distributed through popular messaging platforms including WhatsApp and Telegram, apps widely used by diaspora communities, activists, and journalists to communicate securely and stay connected with contacts inside Iran. By embedding malicious payloads or links within these trusted communication channels, operators increase the odds that a target will open a file or click a link they believe came from a known contact.

Once installed on a Windows device, malware of this type is typically capable of harvesting data, monitoring communications, and providing attackers with a foothold for ongoing surveillance. The coordinated nature of this advisory, spanning three separate national security agencies, underscores how seriously Western governments are treating the threat this campaign poses to individuals living far outside Iran's physical reach.

Who Is Being Targeted: Dissidents, Journalists, and Diaspora Communities

The advisory specifically names dissidents, activists, and journalists as the primary targets of the Chosen Brick campaign. This fits a well-documented pattern among authoritarian states: rather than limiting surveillance to domestic critics, intelligence services extend their reach to diaspora populations, exiled journalists, and human rights defenders operating from abroad.

For these communities, the stakes of a compromised device go far beyond stolen passwords or financial fraud. A successful infection can expose sensitive contacts, reveal sources, and put family members still living inside Iran at risk of retaliation. This is precisely why the individuals targeted by campaigns like Chosen Brick often rely so heavily on encrypted messaging apps such as WhatsApp and Telegram in the first place, and why attackers have adapted their tactics to exploit that trust.

The use of state resources to target specific individuals, rather than casting a wide net for financial gain, distinguishes this campaign from most cybercrime. It reflects a geopolitically motivated operation with intelligence-gathering as its primary goal, a pattern seen across the broader region where Middle East ransomware activity has also increasingly tracked alongside political tensions rather than purely opportunistic targeting.

Why a VPN Alone Won't Stop State-Sponsored Malware

A VPN encrypts your internet traffic and masks your IP address, which is valuable for protecting general browsing privacy and evading network-level surveillance or censorship. But it does nothing to stop malware once it has been delivered directly to a device through a messaging app, a malicious file, or a compromised link.

Chosen Brick illustrates this limitation clearly. If a target opens an infected file sent through WhatsApp or Telegram, a VPN running in the background will not detect the malicious payload, prevent its execution, or stop it from harvesting data already stored on the device. State-sponsored operations like this one are specifically engineered to bypass the assumption that encrypted messaging or network privacy tools alone equal safety.

This doesn't mean a VPN is useless. It remains an important layer for protecting metadata and location information. But for anyone facing a nation-state level threat, it has to be treated as one piece of a much larger security strategy.

Practical Defense Steps for At-Risk Individuals

For journalists, activists, and members of diaspora communities who may be realistic targets of state surveillance, layered defenses matter more than any single tool. Consider the following:

  • Keep operating systems and messaging apps updated, since patches often close the exact vulnerabilities malware like Chosen Brick exploits.
  • Avoid opening unexpected files or links, even from known contacts, and verify unusual requests through a separate communication channel.
  • Use device compartmentalization, keeping sensitive work on a separate device from everyday personal use where possible.
  • Enable app-level security features such as two-factor authentication and disappearing messages on platforms like Telegram and WhatsApp.
  • Run reputable endpoint security or mobile threat detection tools designed to catch spyware behavior, not just traditional viruses.

What This Means for You

Most readers are not likely to be direct targets of an intelligence service. But the Chosen Brick disclosure is a useful reminder that surveillance malware increasingly arrives through the apps people trust most, not through obviously suspicious channels. Anyone who communicates with contacts abroad, works in journalism or activism, or handles sensitive information should assume that trusted platforms can still be exploited as delivery mechanisms.

The broader lesson extends beyond Iran specifically. State-linked cyber operations, whether surveillance-focused campaigns like Chosen Brick or the ransomware operations increasingly affecting the wider region, are shaped by geopolitics as much as by opportunity. Understanding that context helps explain why certain individuals and organizations face persistent, targeted threats rather than generic cybercrime.

Actionable Takeaways

If you or someone you know may be at elevated risk due to journalism, activism, or diaspora ties to a region experiencing this kind of state-sponsored targeting, treat your VPN as one layer among several, not a complete solution. Keep devices updated, scrutinize unexpected files and links even from trusted contacts, separate sensitive work from personal use where feasible, and consider dedicated endpoint protection built to detect spyware behavior. Staying informed about disclosures like the Chosen Brick advisory is itself a form of defense: knowing how these campaigns operate makes it easier to recognize the warning signs before a device is compromised.