The intelligence and security agencies of Britain, the USA, and the Netherlands have issued a joint warning detailing a cyber espionage campaign that, according to them, agents affiliated with the Iranian government are using to target opponents, activists, and journalists in various countries.
Methods of Infiltration and Information Theft
According to this warning, attackers pose as friends, acquaintances, or technical support staff of messaging apps to gain the trust of individuals, and then encourage them to install a seemingly legitimate application or open a file, such as a medical test result.
Read more: Sisi asked bin Salman to negotiate with Ansar Allah
These organizations have warned that malware installed on computers through this method can access victims' messages, emails, and personal information. Additionally, this malware can take screenshots of the computer and, in some cases, record audio and video of online meetings.
This new warning, published on September 15, 2026 (Shahrivar 24), is the result of cooperation between the National Cyber Security Centre of Britain, the Federal Bureau of Investigation (FBI) of the USA, and AIVD, the intelligence and security service of the Netherlands. These three entities have also released technical information and recommendations for identifying attacks and reducing the risk of device contamination.
Malware “Chosen Brick” and “Heavygram”
The National Cyber Security Centre of Britain has named the malware used in these attacks “Chosen Brick.” This agency states that at least since 2025, individuals in various countries, including Britain, the USA, and the Netherlands, have been targeted using this malware family.
The FBI has also introduced a malware with similar characteristics called “Heavygram” in a separate report, stating that attackers began using various samples of it from the fall of 2023. This report is based on the analysis of seven malware samples obtained during this agency's investigations.
This new warning provides further details on the methods of infiltrating victims' computers, the stealth of the malware, and the types of information that attackers are capable of stealing. The FBI had previously warned on March 20, 2026, about the use of Telegram by agents linked to the Iranian Ministry of Intelligence to control malware installed on victims' devices.
In the new report, the FBI attributes the campaign under investigation to cyber agents of the Islamic Republic's Ministry of Intelligence, focusing on malware installation and access to the victim's device.
The joint warning from these three entities particularly emphasizes the method of infiltration used by attackers. The first stage of an attack typically does not begin with direct access to computer systems but rather by establishing communication with the target individual. Attackers research the individual beforehand to learn about their interests, relationships, or topics related to their life and work.
Once communication is established, the attacker attempts to convince the individual to receive and open a file or install an application that seemingly relates to the conversation topic. In some cases, the sent file is designed to resemble an MRI scan result.
Additionally, attackers have used the names and appearances of well-known applications, including AI video production software or password management programs. These methods help attackers divert the user's attention from the malware's activities.
Read more: Houthis: Saudi attacks on Yemen in the past 12 years have been unjustified · Secretary of the Russian Security Council: The West seeks to weaken Iran and Russia's positions in the South Caucasus




