US, UK and Dutch Agencies Reveal Iranian Surveillance Tool That Hides Inside Telegram

A joint government report names 'Chosen Brick', a spying program linked to Iranian operators that uses Telegram to receive stolen data and issue commands.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial style, 16:9 framing
Share

Key points

  • US, UK and Dutch government agencies jointly published a report exposing an Iranian surveillance tool called "Chosen Brick".
  • The malware uses Telegram, a widely used encrypted messaging app, as its command channel: operators send orders and collect stolen data through an ordinary-looking chat service.
  • The FBI called out the Telegram abuse in its portion of the advisory.
  • Attribution sits with Iranian operators, though the advisory does not name a specific group by its tracking label.

Governments in three countries have pulled back the curtain on a piece of Iranian spyware, meaning software secretly installed on a target's device to watch what they do, called "Chosen Brick." The advisory, jointly published by agencies from Washington, London and The Hague and first flagged by SecurityWeek, is the clearest official description yet of how the tool works.

What stands out is how the operators run it. Rather than building a custom hidden server to control their malware, which would be expensive to host and easier for security researchers to find and block, they routed everything through Telegram. Because Telegram traffic looks the same as any ordinary user chatting, it blends in. The FBI highlighted this choice directly in the advisory.

How does hiding inside Telegram work?

Telegram's servers carry a large share of global messaging traffic, so connections to them are rarely blocked. The operators registered a Telegram bot, a simple automated account, and programmed Chosen Brick to contact that bot whenever it needed to send stolen information or receive new instructions. To a company's network filters, the connection looked like someone reading messages.

This technique, broadly called living off trusted services, is tracked across multiple nation-state campaigns because it is genuinely hard to block without also disrupting legitimate business use of the same platform. We covered a related Iranian approach in August, when Kaspersky reported the Cav3rn framework hiding commands inside Google and DNS traffic.

Who is behind this, and who is at risk?

Attribution points to Iran, though the advisory stops short of naming a specific hacking group. Security vendors track several Iranian clusters with overlapping capabilities here: Charming Kitten (also tracked by CrowdStrike as Refined Kitten) and Tortoiseshell both have documented histories of deploying surveillance tools against dissidents and government staff. Whether Chosen Brick maps cleanly to one of those clusters, or represents a separate capability, is not established to a level I'd call high confidence.

The realistic target list is people Iran's government wants to monitor: activists, diaspora communities, journalists covering Iranian affairs, and staff at Western government agencies.

Should ordinary people be concerned?

For most people, direct risk is low. Chosen Brick appears aimed at specific targets, not broad criminal profit. If you work in policy or journalism related to Iran, treat this as a genuine signal.

Practical steps aren't complicated. Keep your phone and laptop updated, because Chosen Brick, like most spyware, needs an entry point that patches close. Be cautious about files or links sent through encrypted apps: Telegram and WhatsApp do not verify who is really sending you something. If your organisation might attract state-level interest, tell your IT team about any unusual device behaviour.

This advisory maps the capability clearly. What analysts should watch now is who Iran is running Chosen Brick against, because the targeting picture is still thin.

© 2026 Threat Vectr