This post is also available in:
Targeted cyber-espionage does not always begin with a technical exploit. For journalists, activists and other high-risk individuals, attackers can spend considerable time studying their targets, impersonating trusted contacts and building enough credibility to convince them to open a seemingly legitimate file.
A joint warning from U.S., British and Dutch security agencies describes an Iranian-linked campaign using exactly this approach to install Chosen Brick, Windows spyware designed for long-term surveillance. The malware has been associated with Iranian cyber operations since at least 2025, while related malware tracked by the FBI as Heavygram dates to 2023.
The attack begins with spear phishing and social engineering. Operators research an individual before contacting them through services such as WhatsApp or Telegram, sometimes maintaining the conversation before sending the malicious payload.
According to Cyber News, the files are customized to fit the story. Authorities have observed fake versions of applications including Telegram, KeePass, Norton Antivirus and AI tools. In one particularly tailored case, attackers sent what appeared to be MRI scan results to persuade the recipient to open the file.
Once executed, it installs additional malware and establishes persistence on the Windows computer, allowing it to remain active after reboots.
Its surveillance capabilities extend well beyond stealing documents. The spyware can capture screenshots, record microphone audio, collect files and obtain information from email and messaging services. It can also install additional malware or delete information from the compromised device.
For command and control, the malware makes unusual use of Telegram infrastructure. Investigators found that individual victims could be assigned separate bot IDs, allowing operators to communicate with infected systems and extract information while separating targets from one another.
The collected material can provide intelligence beyond the contents of a computer. Repeated screenshots, messages, and communications can expose a person’s contacts, movements, and daily routines, potentially allowing intelligence operators to map the wider network surrounding a single victim.
Authorities also warn that attackers may deliberately shift from corporate devices to personal computers when workplace security blocks an intrusion. This means stopping an attempted malicious download on a protected device may not end the campaign if the attacker continues the relationship through another channel.
The activity has particular relevance to national security because the agencies describe it as part of state-linked surveillance targeting dissidents, journalists and activists internationally. Compromising one individual can provide information about many others connected to them.
The defensive advice is comparatively simple: treat unexpected downloads with caution even when they arrive through an apparently trusted conversation, keep systems updated, use strong authentication and obtain software from trusted sources.
The spyware illustrates why targeted espionage remains difficult to stop. The malware provides the surveillance capability, but the crucial first step is often human rather than technical: convincing the intended victim that the malicious file is something they actually want to open.


























