Security.io Intelligence DeskWednesday, 16 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Threat Intelligence · Executive briefing

CHOSEN BRICK hunts high-risk Windows users

A joint UK, US and Dutch advisory supplies concrete Windows persistence artefacts for CHOSEN BRICK, an Iranian state-linked surveillance campaign targeting dissidents, activists and journalists.

Threat IntelligenceEndpoint SecurityIncident Response
Why it is in today’s brief

The campaign has operated since at least 2025, but the new joint government guidance supplies concrete persistence artefacts and documents a fallback from managed to personal devices. Publication-window reporting brought that operational detail into enterprise view. It warrants inclusion because organisations supporting high-risk individuals need a protective-security and BYOD response that ordinary phishing controls do not provide.

Read first

The NCSC, FBI and AIVD have published joint guidance on CHOSEN BRICK, persistent Windows malware delivered through tailored WhatsApp and Telegram social engineering. The advisory provides Run-key values, filenames, mutexes, a nonstandard directory and behavioural guidance.

Act now

Identify employees and affiliates with elevated Iran-related targeting risk.

Accountable owner

Threat-intelligence leader with endpoint, protective-security, legal and HR owners

Decision horizon

Identify high-risk people and run the published endpoint hunt today; escalate any execution evidence immediately.

AssessmentHigh confidence
Emerging riskAdditional victim regions, variant artefacts, named infrastructure, expanded delivery themes or evidence that enterprise identities and systems are being targeted more broadly.

What happened

On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Netherlands’ AIVD released joint guidance on CHOSEN BRICK, a Windows malware family used against dissidents, activists and journalists. The authorities say the campaign has targeted individuals in the United Kingdom, United States and Netherlands from at least 2025. All observed malware instances described by the NCSC targeted Windows.

The delivery chain begins with rapport-building over WhatsApp or Telegram and uses files presented as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass or MRI results. If delivery to a work-managed device fails or appears risky, the advisory says the actor may ask the target to open the file on a personal device. Opening the tailored file displays a plausible screen while a core malware component executes in the background.

Observed persistence includes the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, value names SMQDService and winappx, executables smdqservice.exe and winappx.exe, and mutexes ytyjyujyu and noi672pp434awkc12f. A common additional-malware location is C:\Windows \SysWOW64, including the space after Windows. The advisory warns that names and locations can change, so these artefacts are not exclusive indicators.

CHOSEN BRICK can capture screens and audio, collect browser-accessible Telegram and WhatsApp data, steal email, download files and delete or wipe data. The advisory says exfiltration can use per-victim Telegram bots and cloud object stores including VultrObjects and StorjShare. The cited sources did not publish a victim count or a complete list of compromised organisations. Attribution posture: NCSC, FBI and AIVD attribute CHOSEN BRICK activity to Iranian state cyber actors; the advisory does not identify a named individual operator.

Why this matters now

The campaign targets people rather than conventional enterprise boundaries. The advisory says actors may begin on a corporate device and then encourage the target to use a personal device when managed controls block delivery. Organisations supporting journalists, activists or dissidents therefore need a protective-security model that can offer assistance beyond owned endpoints without covertly monitoring personal devices.

The malware’s surveillance functions create consequences beyond data loss. Screen and microphone capture, messaging-data collection, email theft and pattern-of-life information can expose contacts and physical routines. The NCSC says personal details from previous victims have appeared on pro-Iranian leak sites, raising potential safety concerns that require coordination with legal, human resources and protective-security teams.

The published artefacts are useful but explicitly non-exclusive. A clean search for two mutexes or Run-key values cannot close an investigation after a user executed a tailored lure. Teams must join endpoint evidence, messaging history, browser downloads, Defender configuration, outbound cloud-storage access and personal-device support.

The decision for security leaders

Establish a high-risk-person protection process that joins threat intelligence, endpoint security, legal, human resources and physical safety. Eligibility should be based on evidenced targeting exposure, not seniority alone, and should include a confidential path for reporting suspicious personal-device contact.

Authorise endpoint teams to hunt the published artefacts while requiring broader behavioural investigation after lure execution. Because filenames and persistence values can change, negative indicator results must not overrule evidence from messaging, downloads, process execution, Defender exclusions or unusual cloud-storage traffic.

Define how the organisation can assist with personal devices lawfully and voluntarily. The operating model should cover consent, evidence handling, privacy boundaries, replacement devices, account revocation and referral to law enforcement or protective services.

Evidence of closure

  • Endpoint hunt records disposition for every published artefact match.
  • High-risk-person register has approved eligibility and confidential reporting routes.
  • Personal-device assistance procedure documents consent and evidence-handling boundaries.
  • Affected-host investigation validates Defender settings, persistence, processes and outbound traffic.

The Security.io assessment

This is a targeted espionage and surveillance campaign, not evidence of mass compromise through WhatsApp, Telegram or the named legitimate applications. Infection requires the target to download and execute a tailored Windows file. The authoritative guidance provides sufficiently precise artefacts for immediate hunting while warning against treating them as exhaustive.

The most material enterprise feature is the deliberate move from managed to personal devices when corporate controls resist delivery. That tactic exploits the gap between organisational duty of care and technical ownership, particularly for journalists and others whose personal relationships and routines are part of the intelligence objective.

Confidence is high in the campaign description and attribution posture because three national authorities issued coordinated guidance. Individual compromise still requires host or account evidence. Personal details appearing on aligned leak sites can increase safety consequences, but absence from such sites does not demonstrate that a suspected device is clean.

Questions for the morning meeting

  • Which employees or affiliates face elevated targeting because of journalism, activism or links to Iran?
  • Can corporate security assist when attackers move delivery from managed devices to personal Windows systems?
  • Are the published Run-key values, mutexes and paths searchable across retained endpoint telemetry?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →