← InsightsCyber

Your people’s messaging apps are an attack surface. Treat them like one

NCSC, the FBI and the Dutch AIVD have exposed CHOSEN BRICK, Iranian spyware delivered through WhatsApp and Telegram conversations. The lesson reaches well beyond its targets.

What happened

On 15 September the UK’s National Cyber Security Centre, the FBI and the Netherlands’ General Intelligence and Security Service (AIVD) published a joint advisory on CHOSEN BRICK, a Windows malware family that Iranian state actors have used since at least 2025 against people in the UK, the United States, the Netherlands and elsewhere.

According to the advisory, the actors impersonate contacts on messaging apps such as WhatsApp and Telegram, build rapport, and tailor the lure to the target’s interests — in one case using fake MRI results. The target is persuaded to install what looks like legitimate software. Once running, CHOSEN BRICK collects contacts, emails and social media messages, captures the screen and can access the microphone. It persists across reboots. Reporting on the advisory lists disguises including AI video tools, antivirus software, Telegram itself and a password manager, and notes that the malware uses Telegram’s API and commercial cloud storage for command and exfiltration.

The named targets are dissidents, activists and journalists. It would be easy for a business to read the headline and move on. We think that would be a mistake.

Why it matters beyond the targets

Three things in this advisory apply to almost any organisation.

The conversation happens where your controls are not. Security programmes are built around corporate email: filtering, link rewriting, attachment sandboxing, user reporting buttons. None of that sees a WhatsApp chat on a phone, or a Telegram Desktop session on a laptop. Attackers have noticed. Impersonation over messaging apps is now a routine route into finance teams and executive assistants, not just a state-actor technique.

Rapport beats suspicion. The lure here is not a clumsy phishing email. It is a patient conversation with someone who seems to know you, about something you care about. AI makes that patience cheap to scale — convincing, personalised messages in any language, at volume.

The payload still has to run. For all the sophistication of the approach, the attack depends on a user installing and running a file. That is the step most organisations can actually control.

What we would do

For most organisations, a proportionate response is five actions, in this order:

  1. Enforce application control on Windows endpoints. Allow only approved, signed software to run for standard users. This single control neutralises the fake-installer step regardless of how convincing the conversation was.
  2. Identify your high-risk people. Executives, their assistants, finance approvers, IT administrators and anyone publicly visible. Give them a short, specific briefing on messaging-app impersonation, and a way to verify a contact through a second channel.
  3. Watch for the network behaviour. Use the indicators in the advisory, and more durably, alert on unexpected connections from endpoints to messaging-platform APIs and consumer cloud storage that your business does not use.
  4. Hunt for persistence. Review registry run keys and scheduled tasks across the estate for entries that do not match approved software.
  5. Set a messaging-app policy people can follow. Decide which apps are permitted for work, on which devices, and how staff should report a suspicious conversation — then make reporting as easy as it is for email.

If you run a managed detection and response service, ask your provider directly whether they have ingested the CHOSEN BRICK indicators and what visibility they have of messaging-app traffic. The answer will tell you a lot about the gap.

Questions we are asked

We are not a target for Iranian intelligence. Does this matter to us?

The specific campaign targets dissidents, activists and journalists. The technique does not care who you are. Building rapport over WhatsApp or Telegram, impersonating a known contact and sending a disguised installer is exactly how financially motivated groups reach finance teams, executives and IT administrators too.

Should we ban WhatsApp and Telegram on work devices?

A ban rarely holds and usually pushes the conversation to personal phones, where you have no visibility at all. It is more effective to control what can be installed and run on work devices, monitor for the network behaviour this kind of malware relies on, and train high-risk staff on this specific approach.

What is the single most useful control?

Stopping users from running unapproved executables on Windows endpoints. CHOSEN BRICK depends on a target installing a file disguised as a legitimate application. Application control removes that step, whatever the lure.

Sources

  1. UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists National Cyber Security Centre
  2. CHOSEN BRICK Malware Lets Iranian State Hackers Steal Emails, WhatsApp and Telegram Data Cyberpress
  3. NCSC and Allies Warn of Iranian Spyware Campaign Infosecurity Magazine

This piece was drafted with AI assistance from the sources listed above. The views are Rothian’s; the facts belong to the sources, and every claim links back to one.