What happened
On 15 September 2026, the UK National Cyber Security Centre, the FBI and the Netherlands’ AIVD released joint guidance on CHOSEN BRICK, a Windows malware family used against dissidents, activists and journalists. The authorities say the campaign has targeted individuals in the United Kingdom, United States and Netherlands from at least 2025. All observed malware instances described by the NCSC targeted Windows.
The delivery chain begins with rapport-building over WhatsApp or Telegram and uses files presented as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass or MRI results. If delivery to a work-managed device fails or appears risky, the advisory says the actor may ask the target to open the file on a personal device. Opening the tailored file displays a plausible screen while a core malware component executes in the background.
Observed persistence includes the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, value names SMQDService and winappx, executables smdqservice.exe and winappx.exe, and mutexes ytyjyujyu and noi672pp434awkc12f. A common additional-malware location is C:\Windows \SysWOW64, including the space after Windows. The advisory warns that names and locations can change, so these artefacts are not exclusive indicators.
CHOSEN BRICK can capture screens and audio, collect browser-accessible Telegram and WhatsApp data, steal email, download files and delete or wipe data. The advisory says exfiltration can use per-victim Telegram bots and cloud object stores including VultrObjects and StorjShare. The cited sources did not publish a victim count or a complete list of compromised organisations. Attribution posture: NCSC, FBI and AIVD attribute CHOSEN BRICK activity to Iranian state cyber actors; the advisory does not identify a named individual operator.
Why this matters now
The campaign targets people rather than conventional enterprise boundaries. The advisory says actors may begin on a corporate device and then encourage the target to use a personal device when managed controls block delivery. Organisations supporting journalists, activists or dissidents therefore need a protective-security model that can offer assistance beyond owned endpoints without covertly monitoring personal devices.
The malware’s surveillance functions create consequences beyond data loss. Screen and microphone capture, messaging-data collection, email theft and pattern-of-life information can expose contacts and physical routines. The NCSC says personal details from previous victims have appeared on pro-Iranian leak sites, raising potential safety concerns that require coordination with legal, human resources and protective-security teams.
The published artefacts are useful but explicitly non-exclusive. A clean search for two mutexes or Run-key values cannot close an investigation after a user executed a tailored lure. Teams must join endpoint evidence, messaging history, browser downloads, Defender configuration, outbound cloud-storage access and personal-device support.
The decision for security leaders
Establish a high-risk-person protection process that joins threat intelligence, endpoint security, legal, human resources and physical safety. Eligibility should be based on evidenced targeting exposure, not seniority alone, and should include a confidential path for reporting suspicious personal-device contact.
Authorise endpoint teams to hunt the published artefacts while requiring broader behavioural investigation after lure execution. Because filenames and persistence values can change, negative indicator results must not overrule evidence from messaging, downloads, process execution, Defender exclusions or unusual cloud-storage traffic.
Define how the organisation can assist with personal devices lawfully and voluntarily. The operating model should cover consent, evidence handling, privacy boundaries, replacement devices, account revocation and referral to law enforcement or protective services.
Evidence of closure
- Endpoint hunt records disposition for every published artefact match.
- High-risk-person register has approved eligibility and confidential reporting routes.
- Personal-device assistance procedure documents consent and evidence-handling boundaries.
- Affected-host investigation validates Defender settings, persistence, processes and outbound traffic.
The Security.io assessment
This is a targeted espionage and surveillance campaign, not evidence of mass compromise through WhatsApp, Telegram or the named legitimate applications. Infection requires the target to download and execute a tailored Windows file. The authoritative guidance provides sufficiently precise artefacts for immediate hunting while warning against treating them as exhaustive.
The most material enterprise feature is the deliberate move from managed to personal devices when corporate controls resist delivery. That tactic exploits the gap between organisational duty of care and technical ownership, particularly for journalists and others whose personal relationships and routines are part of the intelligence objective.
Confidence is high in the campaign description and attribution posture because three national authorities issued coordinated guidance. Individual compromise still requires host or account evidence. Personal details appearing on aligned leak sites can increase safety consequences, but absence from such sites does not demonstrate that a suspected device is clean.
Questions for the morning meeting
- Which employees or affiliates face elevated targeting because of journalism, activism or links to Iran?
- Can corporate security assist when attackers move delivery from managed devices to personal Windows systems?
- Are the published Run-key values, mutexes and paths searchable across retained endpoint telemetry?