A Joint Warning From Three Countries

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have jointly exposed an Iranian state-linked spyware operation called CHOSEN BRICK. The advisory, issued by the FBI, the UK's National Cyber Security Centre (NCSC), and the Dutch AIVD, describes a surveillance tool built to hijack microphones and messaging apps on victims' devices, effectively turning personal phones and computers into listening devices for Iranian intelligence.

The campaign has reportedly been active since 2023, with the malware also referenced under the name HEAVYGRAM in related technical writeups. Its purpose, according to the agencies, is straightforward and troubling: to track and surveil dissidents, activists, and journalists who criticize the Iranian government, regardless of where in the world they live.

How CHOSEN BRICK Spyware Operates

What makes CHOSEN BRICK notable isn't just who it targets, but how deeply it embeds itself into a victim's daily communications. Rather than simply logging keystrokes or stealing files, the malware is designed to intercept messaging apps like WhatsApp and Telegram, tools that many activists and journalists rely on precisely because they assume end-to-end encryption keeps their conversations private.

By compromising the device itself rather than trying to break the encryption in transit, the malware sidesteps that protection entirely. Once installed, it can also activate a device's microphone, turning a phone sitting on a desk or in a pocket into a covert audio recorder. This is a pattern that has become increasingly common in state-sponsored spyware: attackers no longer need to defeat strong encryption if they can simply take over the endpoint where messages are typed and read.

We previously covered the initial joint disclosure of the Chosen Brick malware campaign, which outlined how the three agencies coordinated their findings after identifying overlapping indicators of compromise across multiple countries. The latest reporting builds on that advisory with more detail on the malware's targeting and technical behavior.

Who Is Being Targeted, and Why It Matters Beyond Iran

The individuals named as targets, dissidents, human rights activists, and journalists, are groups that routinely operate under real physical risk when their identities, sources, or communications are exposed. For these users, a compromised device isn't just an inconvenience; it can lead to harassment, arrest, or worse for themselves or the people they communicate with.

This is also a reminder that state-sponsored spyware campaigns are rarely confined to a single country or region. The NCSC, FBI, and AIVD advisory reflects an intelligence-sharing effort precisely because the victims of CHOSEN BRICK are spread across borders. Anyone who works in journalism, activism, or advocacy connected to Iran, even from abroad, may fall within the scope of this kind of targeting.

What This Means For You

Most readers of this article are not likely to be direct targets of a nation-state spyware campaign like CHOSEN BRICK. But the underlying lesson applies broadly: messaging apps are only as secure as the device they run on. Strong encryption protects data in transit, not a phone or laptop that has already been compromised by malware with microphone access and app-level surveillance capabilities.

For journalists, activists, and anyone communicating with sensitive contacts, this advisory is a useful prompt to revisit basic device hygiene: keeping operating systems and apps updated, being cautious about unsolicited links or attachments, and using device-level security features like screen locks and full-disk encryption. Organizations that work with at-risk individuals, including press freedom groups and NGOs, may also want to review their digital security training in light of this specific threat.

It's also worth remembering that a VPN, while useful for protecting network traffic and masking location, does not defend against malware that has already been installed on a device. Spyware like CHOSEN BRICK operates after the network layer, directly on the endpoint, which is why layered security practices matter more than any single tool.

Key Takeaways

The exposure of CHOSEN BRICK by the NCSC, FBI, and AIVD underscores how sophisticated state-sponsored spyware has become, and how deliberately it targets the encrypted messaging apps people trust most. If you or someone you know works in journalism, activism, or advocacy touching on Iran, take this as a moment to audit device security rather than a cause for panic.

Practical steps worth taking now include updating all apps and operating systems promptly, being skeptical of unexpected messages or files even from familiar contacts, enabling two-factor authentication where available, and considering a professional digital security assessment if you handle sensitive sources or communications. Awareness of campaigns like CHOSEN BRICK is the first step toward staying a step ahead of them.