News Room
16
Share
Global Intelligence Alert: Escalation of 'CHOSEN BRICK' Spyware Operations Targeting Dissidents
highState Cyber Warfare

Global Intelligence Alert: Escalation of 'CHOSEN BRICK' Spyware Operations Targeting Dissidents

International security agencies have issued a joint advisory regarding the 'CHOSEN BRICK' spyware, an Iranian state-linked tool. The campaign focuses on the surveillance of activists, journalists, and dissidents.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Global Intelligence Alert: Escalation of 'CHOSEN BRICK' Spyware Operations Targeting Dissidents for ₿ 0.10 BTC. Contact us.

08 October 2026Last updated 08 October 20264 min readReuters
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
High
Actor Type:
Nation-State
Geography:
Middle East
Confidence:
High Confidence
Source:
Reuters
Read Time:
4 min

Executive Summary

In a coordinated effort, the United Kingdom, the United States, and the Netherlands have released a joint cybersecurity advisory detailing the resurgence and evolution of the 'CHOSEN BRICK' spyware. This sophisticated surveillance tool, attributed to Iranian state-linked actors, has been identified in a series of targeted campaigns aimed at compromising the digital privacy of dissidents, human rights activists, and international journalists. The advisory highlights a shift in tactics, moving from broad-spectrum phishing to highly personalized, context-aware social engineering.

Threat Analysis

'CHOSEN BRICK' represents a significant evolution in Iranian state-sponsored cyber capabilities. Unlike previous iterations that relied on rudimentary malware, this version utilizes advanced obfuscation techniques to bypass modern endpoint detection and response (EDR) systems. The threat actors are leveraging zero-day vulnerabilities in mobile operating systems to gain persistent access to target devices, allowing for the exfiltration of encrypted communications, location data, and biometric information.

Technical Details

Technical analysis indicates that the spyware employs a modular architecture. The initial infection vector typically involves a 'watering hole' attack or a spear-phishing link disguised as a legitimate invitation to a regional political forum. Once executed, the payload establishes a command-and-control (C2) connection using domain fronting to mask its traffic as legitimate cloud service requests. The malware is capable of recording audio, capturing screen activity, and intercepting messages from end-to-end encrypted applications by exploiting memory-resident hooks.

Attribution Assessment

Intelligence agencies have linked the development and deployment of 'CHOSEN BRICK' to an Iranian-affiliated APT group known for its focus on regional geopolitical interests. The sophistication of the infrastructure and the specific targeting profile align with historical patterns of Iranian state-sponsored cyber espionage, suggesting a high level of state resourcing and strategic oversight.

Implications

This campaign underscores the growing risk to civil society and the press in an era of persistent digital conflict. By targeting individuals rather than just institutional infrastructure, the actors are attempting to suppress dissent and gather intelligence on opposition movements. The international nature of the victims necessitates a unified global response to protect vulnerable populations from state-sponsored digital surveillance.

Recommendations

Organizations and individuals at high risk should implement strict mobile device management (MDM) policies, including the use of hardware-based security keys. It is recommended to disable unnecessary permissions on mobile devices, regularly update operating systems to the latest security patches, and utilize encrypted communication platforms that have undergone independent security audits. Security teams should monitor for anomalous outbound traffic patterns associated with known C2 infrastructure identified in the joint advisory.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo