If you are searching for CHOSEN BRICK spyware after receiving a suspicious WhatsApp or Telegram message, the first distinction matters: receiving a message does not by itself mean your device is infected. The joint UK NCSC, FBI and Netherlands AIVD advisory describes a targeted campaign in which Iranian state cyber actors build trust with selected people and then try to persuade them to download and open a malicious file on a Windows device.
The documented targets include dissidents, activists and journalists perceived as threats to the Iranian regime. The agencies say CHOSEN BRICK, which the FBI also tracks as HEAVYGRAM, has been used against people internationally since at least 2025.
Once executed, the malware can persist across reboot, capture screen content and microphone audio, steal email and browser-accessible WhatsApp or Telegram information, modify security settings and download additional malware. That makes the important reader question not simply whether a suspicious message arrived, but whether a malicious Windows payload may actually have been executed.
CHOSEN BRICK spyware: work out your exposure state first
1. You only received the message or file
Do not open or install the supplied file. Verify the supposed sender through an independent channel and obtain software only from a direct legitimate source or official app store.
2. You downloaded the file but did not execute it
Do not run it. Preserve enough information for a trusted security team to assess the lure if you are in a high-risk group, and avoid repeatedly opening or testing the file yourself.
3. You opened or executed the file on Windows
Treat the device as potentially compromised. The NCSC advises concerned organisations to involve internal or external IT or security providers and investigate available logs, published indicators, persistence mechanisms and detection signatures.
4. You find no published indicator
Do not treat that as proof the device is clean. The advisory explicitly warns that filenames, directories and Registry value names can change.
5. You are a high-risk individual
Use trusted professional support for investigation and remediation. A single antivirus result, reboot or password change is not enough to establish that a potentially compromised Windows system is safe.

What is CHOSEN BRICK?
CHOSEN BRICK is the NCSC name for a Windows malware family used in a targeted Iranian state cyber campaign. The FBI separately refers to the malware as HEAVYGRAM.
The joint advisory says attackers research their targets and use tailored social engineering rather than sending the same generic lure to everyone. They may pretend to be someone already known to the target or technical support from a messaging platform, then build enough trust to persuade the person to open what appears to be a legitimate application or document.
Observed lures have included files presented as Pictory, RunwayML, Norton Antivirus or NortonLite, Telegram, Adobe Flash Player and KeePass. In other cases, attackers presented files as MRI scan results.
Those examples are evidence of previously observed techniques, not an exhaustive list. A different filename or theme should not automatically be treated as safe.
Who is actually being targeted?
The agencies describe targeted surveillance of dissidents, activists and journalists, including individuals in the UK, United States and Netherlands and targets elsewhere internationally.
This is important because CHOSEN BRICK should not be presented as a mass WhatsApp or Telegram infection affecting every user of those services. The observed campaign is selective and uses detailed knowledge of the intended victim.
Attackers may first approach a work or corporate device. If that route fails or appears likely to trigger security controls, the advisory says they can attempt to shift the conversation toward the target’s personal device.
Does CHOSEN BRICK infect WhatsApp or Telegram?
The evidence does not support saying that WhatsApp or Telegram itself is infected.
WhatsApp and Telegram can be used as communication channels during the social-engineering stage. After CHOSEN BRICK is installed on Windows, the malware has also been observed using Telegram infrastructure for command and control.
The malware can capture copies of Telegram and WhatsApp data accessible through web browsers on the compromised computer. That is different from proving that the underlying encrypted messaging platforms themselves were broken.
Is this a phone spyware warning?
In all CHOSEN BRICK instances observed by the NCSC, the malware targeted the Windows operating system.
That means the current technical advisory supports a Windows compromise investigation. It does not establish an observed CHOSEN BRICK infection of Android or iPhone devices.
That boundary should not be turned into a permanent claim that no future or undiscovered variant could ever target another platform. It describes the evidence available in the September 2026 advisory.
What happens when the malicious file is opened?
The lure is designed to display something that looks legitimate to the victim while malicious activity happens in the background. The file downloads and runs the core CHOSEN BRICK component, giving the attacker control over the Windows device.
The malware has been observed creating persistence, changing Microsoft Defender settings, connecting to command-and-control infrastructure and downloading additional malware.
The NCSC says the malware has not been observed automatically moving laterally to other devices. Because it can download additional malware, however, the advisory notes that additional capabilities could technically be introduced.
Can CHOSEN BRICK survive a reboot?
Yes. The documented malware is persistent.
The advisory says it commonly abuses the current user’s Windows Registry Run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Programs configured there can automatically execute when that user logs in.
Previously observed malicious value names include SMQDService and winappx. These names are examples rather than a complete detection rule. The NCSC specifically warns that the malware can use different filenames, directories or Registry value names.
What can the spyware collect?
The documented command set is broad. CHOSEN BRICK can enumerate processes and system information, capture the screen, activate the microphone, steal email content, collect browser-accessible WhatsApp and Telegram data, download additional files and execute commands through Windows tools.
The malware can also delete files, and the NCSC reports that at least one analysed sample included functionality capable of wiping a computer system.
Screen capture is described as a commonly observed collection technique. The information gathered can expose contacts, location clues and a person’s pattern of life. The NCSC says personal information stolen from some previous victims later appeared on pro-Iranian leak sites.
Can CHOSEN BRICK weaken Windows security?
Yes. The advisory says the malware can add exclusions to Microsoft Defender antivirus in an attempt to evade detection.
This is one reason a reader should not rely on a single antivirus result as definitive evidence that a high-risk device is clean. The documented actor deliberately attempts to interfere with normal defensive visibility.
What should you check after opening a suspicious file?
If you executed a suspicious file matching this campaign pattern, the safest interpretation is potential compromise requiring investigation, not immediate certainty that CHOSEN BRICK is present.
The NCSC recommends that organisations concerned the malware was executed contact their internal or external IT providers. Investigation should include available logging, the published indicators of compromise, the installation and persistence behaviours described in the advisory and the detection signatures provided by the agencies.
For high-risk individuals using personal devices, the advisory specifically recommends that organisations support relevant staff in checking those personal devices too.
Does a missing Registry entry prove the PC is clean?
No.
The named Registry values and file paths are examples from observed infections. The malware can change its filenames, directories and Registry value names, so absence of SMQDService or winappx does not rule out compromise.
The same principle applies to network indicators. The malware has used legitimate services, including Telegram and cloud-storage infrastructure, so seeing traffic to a legitimate service is not automatically proof of infection. Unexpected activity has to be evaluated in context.
What if you received the lure but never opened it?
If you did not execute the supplied file, the documented infection chain has not reached the malware-execution stage described in the advisory.
Do not install software sent through an unexpected attachment or link. Verify the sender independently, and obtain applications from direct legitimate download sites or official app stores.
If you are a journalist, activist, dissident or another person at elevated risk, preserve the suspicious contact details and seek appropriate organisational or national cyber-security support rather than continuing the conversation with the suspected attacker.
What if you already opened the suspicious Windows file?
Do not assume that rebooting the computer, deleting the original download or changing a WhatsApp password resolves the problem. The documented malware survives reboot and operates at the Windows endpoint level.
For a high-risk target, professional investigation is the safer route because remediation decisions can destroy useful evidence or leave persistence undetected. Follow the current joint-agency technical guidance and the advice of a trusted security provider familiar with targeted compromise.
Should you keep using the computer for sensitive work?
TPS cannot establish remotely whether an individual device is compromised. If a high-risk user executed a suspicious payload consistent with the campaign, continuing sensitive activity on that device before trusted investigation can expose additional information if malware is present.
Use an independently trusted device and communication route when seeking incident-response assistance rather than assuming the potentially affected machine is a safe channel.
Can antivirus alone prove that CHOSEN BRICK is gone?
No single negative check can establish that conclusion from the evidence reviewed.
The advisory documents security-tool modification and changing indicators. A complete response may therefore require endpoint investigation, logs, persistence checks, published detection signatures and professional assessment rather than one scan result.
Can it automatically spread across a network?
The NCSC says automated lateral movement has not been observed in the analysed campaign. The malware has focused on individual devices.
However, it can download additional malware. The agencies therefore do not rule out the technical possibility that another payload could introduce capabilities not present in the observed CHOSEN BRICK samples.
What should organisations supporting high-risk staff do?
The NCSC recommends circulating the advisory to people likely to be targeted and supporting investigation of personal devices as well as corporate systems when relevant.
Security teams should use the full current advisory and associated technical analysis rather than reducing detection to one filename or Registry value. The attack depends heavily on tailored social engineering, so reports of unusual contact from supposed acquaintances or messaging-platform support can also matter to the investigation.
Where should a potential victim report the incident?
Reporting routes depend on jurisdiction and organisation. The AIVD says people in the Netherlands who believe they may be victims can report the matter to the AIVD or police. Other countries and organisations have their own national cyber-security, law-enforcement or internal incident-response channels.
There is no single global reporting route established by the evidence reviewed. High-risk users should use the appropriate current national authority or their organisation’s trusted security team.
CHOSEN BRICK spyware: the practical rule
The most important distinction is between contact and execution.
A suspicious WhatsApp or Telegram message can be the beginning of the social-engineering chain, but it is not proof of malware infection. The documented compromise occurs when the target is persuaded to download and execute a malicious Windows file.
If that execution occurred, the risk moves from suspicious communication to potential endpoint compromise. That is when persistence, Defender changes, network activity, additional malware and the published detection signatures become relevant.
Verification note
TPS reviewed the joint NCSC/FBI/AIVD CHOSEN BRICK technical advisory, the NCSC public warning, the AIVD announcement and current corroborating reporting. The core campaign, Windows scope and documented capabilities are primary-confirmed. Individual infection cannot be determined from this article, and published indicators are not exhaustive.
Bottom line
CHOSEN BRICK spyware is a targeted Windows surveillance threat, not evidence that every WhatsApp or Telegram user is under attack.
If you only received a suspicious lure, do not execute the file and verify the sender independently. If you actually opened a suspicious Windows payload and fit the documented targeting pattern, treat the device as potentially compromised and obtain trusted security assistance using the current joint-agency guidance.
Do not rely on one missing filename, one clean scan, a reboot or a password change as proof that a potentially targeted Windows system is safe.