Cyber Threat Intel 5 min read

Three Agencies Blamed Iran for CHOSEN BRICK. Only the FBI Named the Ministry.

CHOSEN BRICK gives every victim their own Telegram bot. The NCSC, FBI and AIVD signed one advisory and stopped at different levels of attribution.

Priya Nair
Data, AI Governance & Policy Analyst
Published 17 Sep 2026, 11:48 AM (SGT)
Share:
A person holding a smartphone in the dark, face lit by the screen A person holding a smartphone in the dark, face lit by the screen Photo by Towfiqu barbhuiya on Pexels
Advertisement

17 SEP 2026 — Three agencies put their names to the same malware advisory on 15 September. Two of them described an Iranian state actor. One named the ministry.

The malware is CHOSEN BRICK to the United Kingdom's National Cyber Security Centre and HEAVYGRAM to the FBI, and it is used against dissidents, journalists and activists rather than against companies.

One Telegram bot for each victim

Security teams will read the command-and-control design twice. Each infected machine gets its own Telegram bot identifier, which the agencies describe as an operational-security measure preventing cross-contamination between victims.

That discipline is unusual. With shared infrastructure, a researcher who finds one victim can enumerate the rest, which is how campaigns are usually sized from outside. With one bot per target, seizing or discovering one channel exposes one person and tells an investigator little about who else is infected.

Stolen material leaves by the same route it is commanded: through the Telegram bot and through the cloud object stores the advisory names as VultrObjects and StorjShare. Consumer messaging platforms for control traffic are not new. Pair that with per-victim isolation and commodity object storage, and you have a design that expects to be hunted.

What it takes from a machine

The capabilities are aimed at surveilling a person, not robbing an organisation. The malware can list running programs, take screenshots, turn on the microphone, copy Telegram and WhatsApp data out of the browser, steal saved passwords and email addresses, download further malware and delete files.

Microphone capture and messenger extraction separate this from criminal tooling. A crew monetising access wants credentials and files. An intelligence service watching a journalist wants to know who they met, what was said in the room, and which sources appear in a chat history.

3Agencies co-sealing the advisory
1Telegram bot per infected device
6Applications impersonated by installers
Mar 2026The FBI alert this updates

Disguised as the tools targets use

The installers impersonate Pictory, RunwayML, Norton Antivirus, Telegram itself, Adobe Flash Player and the password manager KeePass. In some cases the file is dressed as MRI scan results.

Read that list as a targeting document. Two AI video tools and a password manager are the software of someone who produces media and has been told to improve their security practice. The medical lure works on anyone waiting for a result, and works especially well on a person who cannot walk into a clinic at home.

Where the three agencies differ

The NCSC advisory attributes the activity to Iranian state cyber actors and does not name a government body. Its judgement is put in the language of assessment: "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime." The FBI goes further, attributing the malware to Iran's Ministry of Intelligence and Security.

The dates also split. The NCSC describes CHOSEN BRICK as used against people in the United Kingdom, the United States, the Netherlands and elsewhere from at least 2025. The FBI dates the wider campaign to autumn 2023 and publishes this as an update to a March 2026 alert.

Advertisement

Neither is a correction of the other. A joint advisory is a document three services can each sign; the wording settles at the level every signatory will defend. The FBI names a ministry while the NCSC stops at the state. That gap tells you more than a single agreed sentence would.

What to watch

Start with the platform. Command and control that depends on Telegram bots depends on Telegram leaving them running, and published bot identifiers are exactly the kind of indicator a platform can act on at scale. Whether the infrastructure survives publication is the first test of how much this advisory costs the operators.

Then the target list. The three countries named are where the co-sealing agencies have jurisdiction. That reflects who wrote the advisory, not where the victims are. Diaspora communities are not distributed along those lines.

Then the tooling underneath. Nothing here required an exploit, a zero-day or a supply-chain compromise. Access came from a person installing what they believed was a video tool or a password manager, which puts the defence in the hands of people least able to demand help from an employer's security team.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement