British, American and Dutch security agencies have issued a joint warning about spyware they attribute to Iranian state-linked actors targeting dissidents, activists and journalists through tailored messages on WhatsApp and Telegram.
The malware family is known as CHOSEN BRICK. According to the UK’s National Cyber Security Centre, attackers pose as trusted contacts and persuade targets to open malicious files. Some lures have included fabricated MRI results, because apparently “please review this medical document” now requires the same suspicion as an email from a distant millionaire distributing inheritances.
Iran’s embassy in London did not immediately respond to Reuters’ request for comment. The agencies say Iran’s Ministry of Intelligence and Security is behind the activity; that attribution is their assessment, not a court judgment.
What the spyware can do
The advisory says CHOSEN BRICK can steal emails and messages, access contacts and social-media accounts, capture screen content and activate a device microphone. Some victims’ information later appeared on pro-Iranian leak websites, turning private surveillance into public intimidation.
The campaign uses spear-phishing rather than indiscriminate spam. Messages are researched and adapted to a particular person, sometimes impersonating somebody the target knows. That personal detail makes the approach more convincing and explains why ordinary advice such as “look for bad spelling” is no longer enough.

The warning is especially relevant to people connected with Iranian politics, human rights, journalism and diaspora activism, but the defensive lessons are wider. A familiar profile picture does not prove who controls an account. A document expected from a real colleague can still be dangerous if the colleague’s account has been compromised or copied.
How to reduce the risk
Verify unusual requests through a separate channel. If somebody sends a sensitive attachment, call them on a known number or start a fresh conversation using contact details you already hold. Do not use the number included in the suspicious message as your proof that the suspicious message is genuine.
Keep phones, computers and messaging apps updated. Use multi-factor authentication, preferably a passkey or security key where available. Treat requests to disable security settings, install an unfamiliar app or open a password-protected archive as serious warning signs.
High-risk users should seek specialist support before investigating a suspicious file themselves. Opening it repeatedly on different devices is not analysis; it is giving the attacker a small product launch.
Anyone who believes a UK organisation or prominent individual has been targeted can report the incident to the NCSC. Suspicious messages aimed at ordinary consumers can also be forwarded through the established national reporting channels.
For more on platform safety and regulation, read our report on the EU proposal for stronger child protections online.
Why this is political as well as technical
Spyware allows a government or its proxies to reach critics beyond national borders. The objective may be intelligence, but leaking private material also deters speech and damages reputations. That turns cybersecurity into a question of democratic protection: whether journalists and activists can communicate without a foreign intelligence service sitting invisibly in the group chat.
Platforms must keep strengthening detection and notifying targeted users. Governments must publish enough technical information for defenders without exposing investigative methods. Victims need support that recognises reputational harm alongside device compromise.
The OutOut verdict
The clever part of modern spyware is rarely a cinematic green code waterfall. It is a believable message arriving on a busy afternoon from somebody who appears to know your work.
Pause, verify and update. If a contact unexpectedly sends an MRI result, your first diagnosis should be “this conversation requires a phone call”.