Most advisories from the National Cyber Security Centre are written for the people who run networks. This one, published today with the FBI and the Dutch AIVD, is written for people who are being hunted, and for the organisations that employ them. That is worth pausing on before getting into the registry keys.

The advisory describes a malware family the NCSC tracks as CHOSEN BRICK, in use against individuals in the UK, the United States and the Netherlands since at least 2025. It exists so that Iranian state actors can read a person's contacts, emails and messages, watch their screen, listen through their microphone, and work out where they are and who they talk to. In the NCSC's assessment, Iran "almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime", and the same paragraph notes that Iranian intelligence services have, in some cases, "plotted to kidnap or conduct lethal operations against individuals internationally". The personal details of some previous victims have appeared on pro-Iranian leak sites.

So this is not an espionage story in the usual sense, where the thing stolen is a document and the harm is commercial or diplomatic. The thing collected is a life, and the harm is to the person living it. The NCSC's Director of Operations, Paul Chichester, put it plainly in the accompanying release: "The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices."

I want to do three things here. Explain what the advisory actually says, because the technical detail is more interesting than the headline. Set it against what the FBI published about the same malware, which goes further on attribution and on what the tooling can do. And then say what I think the practical consequences are, for people who might be targets, and for the newsrooms, universities, charities and law firms that employ them and whose corporate security controls, it turns out, the attacker has learned to walk around.

The first message is always kind

The attack chain starts with a conversation, not an exploit. The advisory describes Iranian operators making contact over messaging platforms, WhatsApp and Telegram among them, and spending time building rapport before anything malicious is sent. The persona is chosen to fit the target: someone the target already knows, or technical support from the platform itself. The NCSC is explicit that the approach draws on "extensive target knowledge from research conducted in preparation", which is MITRE's T1589, and that the payload is then dressed to match whatever story has been told.

The dressing is the part that tells you who is being targeted. The advisory lists installers posing as Pictory and RunwayML, both AI video tools that a journalist or a content-producing activist might plausibly want; a Norton antivirus package; Telegram itself; Adobe Flash Player, which has been dead since 2020 and still works as a lure; and KeePass, the password manager. Then there is the one everybody will remember: files posing as MRI scan results. If you have spent a week telling someone you are worried about their health, an MRI result is the most natural attachment in the world.

Whatever the wrapper, the behaviour is the same. The file opens something that looks right, a login screen, a scan viewer, an installer, and keeps the person looking at it while, in the background, it fetches and runs the real component. Every observed sample has been for Windows.

The detail in the delivery section that I think matters most is this. The operators often make first contact on the target's work device. If that delivery fails, or the operator judges the risk of detection too high, they ask the target to open the file on a personal device instead. The advisory's own words are that this is done "evading corporate security controls that protect the individual". Read that as an attacker who has learned that a managed laptop with EDR and application control is a hard place to land, and that the same person's home PC is not. The corporate estate is being used as a reconnaissance surface and then deliberately stepped off.

I wrote in July that the Qantas breach was a phone call, and the pattern here is the same one with the stakes raised. No zero-day. A human being, a plausible story, and enough patience to wait for the moment when the target is tired, worried, or grateful.

What it does once it is in

CHOSEN BRICK persists through the most ordinary mechanism there is: a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, which runs the malware every time that user logs in and needs no administrative rights to set (T1547.001). It adds exclusions to Microsoft Defender so that its own directories are not scanned (T1685). And it registers a mutex so that only one copy runs; the NCSC gives the two most common as ytyjyujyu and noi672pp434awkc12f (T1480.002), which are the sort of strings a detection engineer can do something with.

Command and control goes over Telegram's bot API (T1102.002). Each victim's device talks to a different bot, unique to them, which the advisory describes as an operational security precaution to prevent cross-contamination between victims. It is also a way of making one victim's discovery useless for finding the others: there is no shared domain to block, no shared bot token to sinkhole, and the traffic goes to api.telegram.org like everybody else's.

The task list is what you would expect from a surveillance implant and one or two things you would not. Through the bot the operator can enumerate processes and system information, capture the screen, turn on the microphone, lift Telegram and WhatsApp data out of web browsers, pull email, download further malware, delete files, and wipe the machine. The advisory describes screen capture as a feature commonly seen in these infections, and says why: it is how the actor identifies the victim's contacts, location and pattern of life. In some cases the material has then been published to harass the victim.

Exfiltration goes out through the Telegram bot and through ordinary commercial object storage, VultrObjects and StorjShare among them (T1567.002). Newer variants push the Telegram traffic through HTTPS or SOCKS5 proxies (T1090.002), and the domain list the NCSC asks defenders to look for includes two commercial proxy providers, iproyal[.]com and lightningproxies[.]net (both sell residential proxies, though the advisory does not say which product was used), alongside backblazeb2[.]com, vultrobjects[.]com, storjshare[.]io and api[.]telegram[.]org. Every one of those is a legitimate service. The advisory's guidance is to investigate connections to them "where not expected as part of normal business", which is a polite way of saying that if your DNS logs cannot tell you whether anyone in the building uses Telegram, you have a logging problem before you have a malware problem.

One more detail for the people who write detections. When the implant downloads additional tooling, the most common drop location is C:\Windows \SysWOW64. That is not a typo in the advisory. There is a space after Windows, so it is a directory the actor creates, sitting next to the real one, that no legitimate installer would ever write to. The advisory does not say the malware moves laterally on its own, and says it has focused on single devices, but it can fetch and persist further payloads, so the capability to go wider exists even if it has not been used.

What the FBI adds

The NCSC release points to a 55-page FBI FLASH published the same day as further technical analysis of the malware, and it is worth reading alongside the UK document because the two agencies have made different editorial choices.

The FBI names the malware HEAVYGRAM, and it names the customer. In the Bureau's assessment the operators are working "on behalf of the Government of Iran’s Ministry of Intelligence and Security (MOIS)", the malware has been in use since the autumn of 2023, and the victim profile is "Iranian dissidents, journalists opposed to Iran, members of organizations with beliefs counter to Government of Iran narratives, and other individuals Iran perceives as a threat to the Iranian government". The NCSC document says "Iranian state cyber actors" and leaves it there. That is a normal difference between the two organisations, and if you are briefing a board the safe formulation is that the UK attributes to the Iranian state and the United States attributes specifically to MOIS.

The FLASH is an update to a shorter one the FBI issued on 20 March 2026, and the March document carries a paragraph the September one does not repeat. In July 2025 the persona "Handala Hack" claimed a hack-and-leak operation against people who had voiced views on events in Iran that conflicted with the government's line. The FBI assesses that some of what Handala published was obtained with this malware, and that Handala is linked to "Homeland Justice", another front it says is operated by MOIS cyber actors. That closes the loop the NCSC leaves open when it says victims' details "have appeared on pro-Iranian leak sites": in the FBI's telling, the implant collects, and the persona publishes.

The FBI also widens the picture of first contact a little. Its operators worked over Telegram, WhatsApp and Instagram, and the opening offer was often IT help; some victims were talked into installing AnyDesk and handing over the access code, which needs no malware at all. As the March document puts it, "the malware could be used to target any individual of interest to Iran".

On the tooling itself, the FBI analysed seven samples and the picture is of a modular, unglamorous, entirely adequate piece of software. The Pictory and Telegram lures are Delphi executables that draw a convincing screen; the Pictory sample even opens a real browser to Pictory's checkout page when you press its buy button, which is a nice touch. The persistent implants are Python packed with PyInstaller. They disable Defender for their own paths with Add-MpPreference from PowerShell, and they are tasked through Telegram with short commands: ss for a screenshot, EnableMic to fetch and persist a separate microphone module, OutlookExtract to walk every mailbox in the Outlook client over COM and zip the lot, GetChromePass to decrypt saved Chrome credentials, and GetChromeTelWhat to lift the local storage that WhatsApp Web and Telegram Web keep in the browser. One command replaces the victim's WhatsApp shortcut with a look-alike, Whatssapp.exe, built on Microsoft's WebView2, so that the person keeps chatting through an application the attacker controls. Both FBI documents note that the microphone module was built to record screen and audio while a Zoom session was active.

Two small things from the FBI's sample metadata are worth knowing if you are the person checking a machine. One of the persistent implants carried a code-signing certificate issued by SSL.com that has since been revoked, so a revoked signature on an unfamiliar binary in ProgramData is a signal rather than a curiosity. And the linker metadata the FBI records for the Pictory installer carries an admin flag, which indicates a manifest that asks for elevation at launch, exactly what a person installing a video tool or an antivirus product expects to be asked for and grants without a second thought. A standard user cannot add Defender exclusions, so the lure does double duty: it holds the person's attention and it collects the privilege.

The Dutch angle is shorter and, in one respect, more concrete. The AIVD's statement, published at 16:00 Amsterdam time today, says that victims of the malware in the Netherlands have been informed. It also lists "NortonLite" among the lures, a name the UK document gives simply as Norton Antivirus.

Why the UK is saying this now

The advisory does not arrive in a vacuum, and it helps to know what sits behind it.

In March 2025 the security minister, Dan Jarvis, told the Commons that MI5 had responded to twenty Iran-backed plots presenting potentially lethal threats to British citizens and residents since the start of 2022, and announced that the whole of the Iranian state would be placed on the enhanced tier of the Foreign Influence Registration Scheme. That scheme went live on 1 July 2025, and the enhanced tier explicitly covers activity directed by MOIS and the IRGC. The Home Office has published guidance for people who think they are the victim of transnational repression, most recently updated in May, which defines the problem as crimes directed by foreign states against individuals and lists surveillance, online harassment and attempts to force people to return to their country of origin alongside physical violence.

Today's advisory is the cyber chapter of that story, and I struggle to think of a previous NCSC advisory that published indicators of compromise for an implant whose stated purpose is to help a foreign state find a person. I wrote in August last year that Iran had moved from prepositioning to action against UK organisations. This is the same state, a different target set, and a much older objective. Regimes have always wanted to know what their exiles are saying and to whom. What has changed is that the tooling to find out now costs a Delphi licence and a Telegram account.

It is also, I think, a deliberate contrast to how the commercial spyware conversation has gone. When I wrote about Pegasus in 2021 the difficulty for defenders was that the capability was zero-click, aimed at phones, and beyond the reach of any advice you could give an individual short of "throw the phone away". CHOSEN BRICK is the opposite. It needs a click, it is Windows-only, and every step of it depends on a person doing something that a well-briefed person would not do. That is the good news in the advisory, and the NCSC says as much: "The best defence is for the user/victim to be more aware of social engineering through training."

If you might be a target

The NCSC's own mitigation list is short and correct, and I am going to restate it in the order I would actually do it, because the advisory's audience includes people who have never been told any of this before.

Do not install software that arrives in a chat. Not from a friend, not from "Telegram support", not from someone who has been kind to you for a fortnight. If you need Pictory, go to Pictory's website and download it there; if you need KeePass, go to KeePass's. There is no legitimate reason for anyone to send you an installer, and there is no legitimate reason for an MRI result to be an executable. Windows will show a SmartScreen warning when you run an unrecognised program from the internet, and the advisory is blunt that you should not click through it. That warning is the last control between you and the implant.

Keep Windows and everything on it updating automatically, and keep Defender or another antivirus switched on. The malware adds exclusions to Defender precisely because Defender is in its way. If you want to go further, the Home Office guidance suggests Windows S mode, which only permits applications from the Microsoft Store and would have stopped every lure in this advisory at the door. It is not for everyone, but for a person whose main computing is a browser and a messaging app it is a very strong position.

Turn on two-step verification for your email, your messaging apps and your social media, and prefer a phishing-resistant method where the service offers one. The implant steals saved browser passwords and the local storage behind WhatsApp Web and Telegram Web, which is to say it steals sessions. Two-step verification does not stop a stolen session being used, but it stops the stolen password being used again from somewhere else, and it makes the account recoverable.

If you think you may already have been affected, the advisory gives one check anyone can do. Open a PowerShell or Command Prompt window and run:

reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run

That lists everything set to start when you log in. The two entries the NCSC has seen before are a value named SMQDService pointing at an executable somewhere under C:\ProgramData\SMQDServicePackages (the NCSC prints the filename as smdqservice.exe; the FBI's analysis, which names it eighteen times, has smqdservice.exe, so match on the directory rather than the spelling), and a value named winappx pointing at winappx.exe under C:\Users\All Users\MicrosoftDistribution\sysmain. The advisory is careful to say that these names change and should not be treated as the only indicators, so the better habit is to look at every entry and ask whether you can account for it. Anything you cannot account for, and anything in a directory called MicrosoftDistribution or Drivers\Whatsapp or Drivers\MicDriver under ProgramData, is a reason to stop using the machine and get help.

Getting help, for someone in the UK, means report.ncsc.gov.uk, which is monitored around the clock, and the police if you believe you are at physical risk. The NCSC also runs a set of free services for high-risk individuals, including Personal Internet Protection, which blocks known malicious domains on your personal devices, and the release today specifically encourages people at risk to sign up. The services are opt-in and offered by invitation rather than through a self-service portal; the Home Office guidance gives individualsupport@ncsc.gov.uk as the address to ask. In the Netherlands the AIVD asks people to contact it directly or the police. In the United States the route is the FBI's Internet Crime Complaint Center.

One thing the advisory does not say, which I will. If your work involves Iran and you are given a laptop by an employer, do your Iran-related work on it and nothing else, and keep your personal machine for your personal life. The attacker's documented behaviour is to move from the managed device to the unmanaged one. Give them as little to move to as you can.

If you employ people who might be targets

This is the part of the advisory that I think has been under-read, and it is aimed squarely at organisations.

The NCSC asks that organisations "circulate this with their staff that are likely to be targeted and support them in checking their personal devices too". That is an unusual request from a national authority and it reflects the attacker's documented behaviour. If you are a newspaper, a broadcaster, a university department with Iranian scholars, a human rights NGO, a law firm acting in an Iranian matter, or a diaspora organisation, some of your people are in the target set, and the attacker has already worked out that your corporate controls are the reason to go after their home PC instead. Circulating a PDF is not support. Support is a named person they can bring a suspicious message to, a willingness to look at a personal laptop without judgement, and a policy that says doing so is not a disciplinary matter.

On the technical side, the advisory's list for network administrators is the standard one and it is standard because it works: phishing-resistant MFA, managed devices with application allowlisting and antivirus, the email provider's scanning switched on, endpoint and network monitoring, and a search of collected logs for the indicators. I would add three things that follow from the detail.

First, decide whether Telegram is a business tool in your organisation, and if it is not, alert on api.telegram.org from endpoints. The per-victim bot design means you will never get a bad domain to block; the only signal you will get is that a machine which has no reason to talk to Telegram's bot API is doing so. The same applies to the object-storage and residential-proxy domains the NCSC lists.

Second, alert on Add-MpPreference and on any creation of a Defender exclusion, and treat a directory named C:\Windows \SysWOW64 with a space in it as a confirmed indicator rather than a suspicious one. Both of these are cheap Sysmon or EDR rules, and between them they would have fired on the samples the FBI describes in most detail.

Third, and this is the one nobody budgets for, extend some of your protection to personal devices for the people in scope. That might be as simple as licensing an endpoint product for a small number of home machines, or pointing those people at the NCSC's free Personal Internet Protection service and helping them ask for it. The advisory's whole point is that the person, not the device, is the target. The protection has to follow the person.

For boards

The three questions I would put to the executive team at the next meeting, if the organisation employs anyone whose work touches Iran.

Who in this organisation is plausibly on a hostile state's list, and do they know that we know? The answer is not "nobody" for any media, academic, legal or civil-society organisation with an Iran-facing portfolio. If the names have never been written down, the people on the list are protecting themselves alone.

If one of them received a message tomorrow from "Telegram support" and opened the attachment on their home PC, how would we find out? If the honest answer is "when their details appear on a leak site", that is the answer to take to the risk committee.

What do we actually do for the personal devices of the people we have just identified? Nothing is a defensible answer only if it is a decision rather than a default. The NCSC has asked employers to support staff in checking personal devices. Decide whether you are going to, and write down why.

The closing observation

There is a temptation, reading a document like this, to file it as somebody else's problem. Most of us are not Iranian dissidents. But the advisory is worth reading by anyone who runs security for people rather than for systems, because it is a clean description of what a patient, well-resourced adversary does when the thing they want is a person. They do not attack the estate. They find the person on the estate, learn what they care about, wait until the estate is out of the way, and then ask nicely. Every control that stops it is a control on the human side: knowing who is at risk, telling them, and giving them somebody to ask. The registry key and the Telegram bot are the easy part.

Sources for this piece are the NCSC advisory and its accompanying release of 15 September 2026, the FBI FLASH published the same day and its predecessor of 20 March 2026, the AIVD statement of 15 September 2026, and the gov.uk material linked above. Quotations are verbatim from those documents. Where the UK and US agencies differ on attribution I have reported both rather than choosing between them.