CHOSEN BRICK: Fake Support Moves Spyware to Personal PCs

Daniel Zimmermann
6 Min Read
A support headset becomes a hook holding a laptop.
Fake support can turn a trusted conversation into spyware access.

When a malicious file would not get through on a work device, the attackers had another request: open it on your personal computer. A September 15 advisory from the UK NCSC, FBI and Dutch AIVD describes that handoff in an Iranian espionage campaign using CHOSEN BRICK spyware against dissidents, activists and journalists. The fake helper was moving the target beyond workplace protections.

The joint report describes activity since at least 2025. A separate FBI update, published the same day under the name HEAVYGRAM, analyzes seven samples and traces use of its investigated malware to autumn 2023. These are new disclosures about an established operation, not evidence that the attacks began this week.

The conversation came before the installer

The joint advisory says operators researched their targets and built rapport over services such as WhatsApp and Telegram, impersonating a familiar contact or platform support. Their files matched the conversation: supposed applications, or even medical scan results. If delivery failed on a corporate device, or detection looked likely, they tried to move the file to a personal device.

That is the consequential trust decision. A blocked file did not become safer because another computer could open it. Moving it changed the protections around the person. The observed CHOSEN BRICK infections targeted Windows; receiving a message alone is not the execution step described in the report.

A convincing window covered the background download

Among the disguises was a purported Pictory installer. The FBI examined a file named Pictory_premium_ver9.0.4.exe that displayed a login window while creating files used by a later stage. Its analysis found an encoded archive containing Python dependencies and a second-stage executable.

Fake Pictory login window shown in the joint CHOSEN BRICK advisory.
The decoy showed a familiar-looking login while malware ran behind it. Source: NCSC, FBI and AIVD, September 15, 2026; © Crown copyright.

The window matters because it gave the victim something plausible to see while another operation happened out of sight. A familiar logo or working-looking login form cannot establish that the program behind it came from the real vendor. The reports describe impersonation of software, not a compromise of Pictory’s official distribution.

The FBI also describes a separate delivery route in which people offered IT services and persuaded victims to obtain AnyDesk, potentially sharing access strings. A legitimate remote-access product and a disguised installer are different routes to the same dangerous decision: letting an unverified helper control what happens on the device. Our guide to blocking remote-access scam software on Windows explains the limits of individual protection settings.

The visible app was only the beginning

CHOSEN BRICK can restart at user login through Windows Run-key persistence and add Microsoft Defender exclusions. The joint report describes a separate Telegram bot identifier for each victim device, giving operators a command channel. That does not mean ordinary Telegram use is evidence of infection.

Its surveillance capabilities include screen capture, microphone recording and collection of email or messaging data. The joint agencies warn that some victims’ personal details appeared on pro-Iranian leak sites. The FBI assesses that the actors in its investigation acted for Iran’s Ministry of Intelligence and Security. The harm extends beyond a slow or unstable PC: stolen communications can expose other people around the target.

If the helper already had you run a file

Stop the interaction and contact a trusted IT or security provider from another device. Preserve the conversation and tell the investigator which personal and work devices were involved. The joint advisory specifically recommends helping at-risk staff investigate personal devices, too. Do not erase a potentially evidential machine before getting that advice.

After evidence is preserved and cleanup is appropriate, removing the visible app may leave startup persistence, a security exclusion or an additional payload. For a personal Windows PC, you can download and install Gridinsoft Anti-Malware, update it, run a Full Scan, review detections, apply cleanup, restart and check whether the original symptoms return. The post-malware Windows audit covers follow-up problems; manual investigation is a fallback, not an extra mandatory cleanup sequence.

Scan files downloaded from this scam.

If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.

Scan after an untrusted support download

A scan cannot retract leaked information or prove that no data was accessed. Recover affected accounts and sessions from a trusted device with your support provider. For the next unexpected request, independently verify the person before installing anything—and treat a request to bypass work protections on a home PC as part of the same incident.

References

  1. NCSC, FBI and AIVD. Iranian Cyber Targeting of Dissidents, Activists and Journalists. Joint advisory, September 15, 2026.
  2. FBI. Update on Government of Iran Cyber Actors’ Deployment of Telegram C2 to Push Malware to Identified Targets. FLASH, September 15, 2026.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?