If you live abroad and speak critically about Tehran, your phone might already be compromised. That is the stark reality behind a joint advisory issued by intelligence agencies in the United States, the United Kingdom, and the Netherlands. Western governments are done whispering about transnational repression. They are naming names, detailing specific malicious tools, and calling out state-backed actors who hunt dissidents across international borders.
The joint warning targets an insidious spyware family tracked by Britain's National Cyber Security Centre as CHOSEN BRICK, while the FBI refers to the underlying operational tooling as HEAVYGRAM. Run primarily through Iran's Ministry of Intelligence and Security, these campaigns aren't using zero-day exploits that cost millions of dollars to develop. Instead, they rely on social engineering, psychological manipulation, and apps you probably use every single day.
How the CHOSEN BRICK Campaign Actually Works
Forget about sophisticated technical break-ins that require Hollywood-style hacking. Iranian state-linked operators take a much simpler path. They slide straight into your direct messages on platforms like WhatsApp and Telegram.
Operators spend time building realistic digital identities, posing as trusted contacts, colleagues, or acquaintances. Once they establish a baseline of trust, they send over a file. It looks harmless. It might be disguised as a password manager like KeePass, a video creation utility called Pictory, or even fake medical records like MRI scans.
Once you open that file on your Windows machine, the payload drops. It sets up a persistent backdoor that communicates back to the operators using Telegram bots. By assigning a unique bot identity to every single victim, attackers ensure that if one channel gets burned or blocked by security researchers, the rest of the operation stays online.
Who Is Being Targeted and Why It Matters
The advisory highlights four specific groups in the crosshairs: dissidents, human rights defenders, journalists, and political activists. Confirmed targeting spans the UK, the US, and the Netherlands, though the actual geographic spread likely covers any region with a vocal Iranian diaspora.
If you are an exile writing critical commentary, running an activist network, or reporting on state abuses from London or Los Angeles, your physical location does not guarantee your safety. Digital surveillance collapses geographic distance. State actors don't need to cross physical borders to steal your emails, read your private group chats, or harvest your contact list.
The Broader Pattern of Transnational Cyber Operations
This advisory doesn't exist in a vacuum. It sits inside a growing catalog of aggressive state-linked cyber activity targeting Western infrastructure and diaspora communities. Earlier this year, the FBI and cybersecurity agencies tracked persona groups like Handala Hack, which claimed responsibility for data leaks and high-profile breaches.
While heavy-hitting attacks target corporate networks or municipal water systems, the campaigns directed at individuals are far more personal. The goal isn't just intelligence gathering. It is intimidation, reputational destruction, and the suppression of dissenting voices who thought they finally found a safe haven abroad.
Practical Steps to Protect Yourself Now
You can't rely on platform security alone to protect you from targeted state-sponsored spear-phishing. If you fall into a high-risk category, you need to change how you handle incoming digital files.
- Verify Out-of-Band: If a contact sends you a software installer, an archive, or a document via WhatsApp or Telegram, call them or message them on a completely different platform to confirm they actually sent it.
- Never Open Unsolicited Files: Treat any unexpected PDF, executable, or compressed folder as hostile until proven otherwise.
- Audit Your Devices: Regularly check your active sessions on messaging apps and enforce hardware-backed multi-factor authentication everywhere.
- Isolate Sensitive Work: If you handle sensitive source material or activist communications, use dedicated, air-gapped or hardened devices that never mix personal web browsing with high-risk advocacy work.
Transnational repression is evolving into a digital war of attrition. Staying safe means assuming that your communications are a target and adjusting your operational security accordingly.