A message from someone you recognize. A document that appears legitimate. Perhaps an MRI result, a software file or something that looks like an ordinary work document.
You open it.
And without realizing it, you may have just opened the door to a surveillance operation.
That is the warning issued by cybersecurity and intelligence agencies in the United Kingdom, United States and Netherlands over a malware campaign known as CHOSEN BRICK, which they say has been used by Iranian state cyber actors to target dissidents, activists and journalists around the world since at least 2025.
The UK National Cyber Security Centre, the U.S. Federal Bureau of Investigation and the Dutch General Intelligence and Security Service, AIVD, have jointly exposed the campaign and attributed it to cyber actors working on behalf of Iran’s Ministry of Intelligence and Security.
CHOSEN BRICK is not designed simply to steal one password. According to the agencies, the Windows malware can collect contacts, emails and social-media messages. It can capture screenshots, access the computer’s microphone, download additional malicious software and even delete files. It is also persistent, meaning it can remain active after the computer is restarted.
But the most revealing part of the operation may not be the malware itself.
It is how the attackers get people to install it.
Rather than simply sending random malicious files to thousands of strangers, Iranian cyber actors have reportedly used messaging platforms including WhatsApp and Telegram to establish contact and build trust. They research their targets and tailor conversations around subjects that are relevant to them.
Once that relationship has been established, the attacker sends a file designed to look authentic.
In documented cases, files have been disguised as MRI scan results. Other lures have appeared to be legitimate applications, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass. The victim sees what appears to be a legitimate program or document while malicious software operates in the background.
This reveals something important about modern cyber espionage.
The weakest point may not be the computer.
It may be trust.
A sophisticated firewall cannot help if a person voluntarily opens a malicious file because it came from someone they believe they know. And for journalists, activists and researchers, relationships built through messaging platforms are often an essential part of their work.
The consequences can extend far beyond stolen files.
The agencies say information taken from previous victims has appeared on pro-Iranian leak sites. Such information can expose contacts, movements and patterns of life, potentially creating physical as well as digital security risks. The AIVD says victims in the Netherlands have already been informed.
The campaign also demonstrates why journalists and human-rights defenders increasingly need to think of digital security as part of personal security.
Protecting a source is no longer only about keeping a notebook locked away. It can mean protecting a laptop, phone, messaging account, email inbox and the people stored inside a contact list.
The basic lesson is simple: never assume that a familiar sender makes a file safe.
Security agencies recommend avoiding software delivered through unexpected attachments or messaging links, keeping operating systems and applications updated, maintaining active antivirus protection and using legitimate download sources.
In the digital age, espionage does not always begin with a dramatic cyberattack.
Sometimes it begins with a conversation.
A friendly message.
A familiar name.
And a file that looks completely normal.





0 Comments