They Could Not Open the File at Work, So the Spies Asked Them to Try at Home
The file would not open on the work device. That should have been the end of the attempt. Instead, the person sending it suggested trying a personal computer. In the CHOSEN BRICK campaign described by British, American and Dutch agencies, moving the conversation away from corporate protections was part of the attack.
The joint advisory, published on 15 September, describes Iranian state cyber actors targeting dissidents, activists and journalists, including people in the Netherlands, UK and US. The AIVD says victims in the Netherlands have been informed. It does not publish a victim count, and BlackTree will not identify individuals or reproduce information that could increase their exposure.
A trusted conversation can carry an untrusted installer
The agencies describe carefully tailored approaches over messaging services, sometimes impersonating known contacts or support staff. Targets are persuaded to open files masquerading as legitimate software, including messaging, antivirus or password-management tools. Other lures resemble medical results. The deception concerns the supplied file, not evidence that the legitimate products themselves were compromised.
In observed cases, the Windows malware persists across restarts, changes antivirus exclusions and uses a per-victim Telegram bot for control. Its capabilities include collecting messages and email, screenshots and microphone audio, alongside further payload delivery. The advisory says automated lateral movement has not been observed. Additional-payload capability should not be reported as proof that it happened.
The personal device is not outside the organisation’s duty of care
The agencies warn that stolen personal details have sometimes appeared on pro-Iranian leak sites, potentially increasing safety risks. A contact list or a sequence of messages can expose more than a document: it may reveal relationships, routines and location. The warning is about targeted surveillance and repression, not a claim of a mass infection affecting all users of the named applications.
For employers and professional bodies supporting high-risk people, the practical lesson is a gap in the usual boundary. A managed endpoint may correctly refuse a file while the targeted person remains under pressure to help a supposed colleague or resolve a supposed support problem. Counting the block as a completed defence misses what happens in the conversation afterwards.
BlackTree’s recommendation is to make that next step explicit. Give staff a trusted route to ask, “This person wants me to move the task to my own laptop; is that safe?” The route should not punish the person for asking or require them to disclose their private messages to an unnecessarily wide audience. Support should be proportionate to the threat and respectful of personal privacy.
Respond without making the target more visible
- Verify the request through a separate trusted channel. A familiar display name or long conversation is not independent verification. Use contact details you already trust, not those supplied with the questionable file.
- Obtain software from its legitimate source. The AIVD advises against installing software delivered through message links or attachments. Do not treat a security-tool label as a guarantee about an installer.
- Keep protective controls enabled. The agencies recommend current software and antivirus, and not ignoring download warnings. A request to bypass them is a reason to pause, not proof that the sender has authority.
- Offer confidential personal-device support. The joint advisory recommends helping potentially targeted staff check personal devices as well as corporate systems. Agree the scope and handling of private data before inspection.
- Escalate suspected compromise using a safe device. Seek qualified help, preserve relevant evidence and avoid using a potentially monitored device to plan sensitive next steps. In the Netherlands, the AIVD or police can receive reports.
- Limit incident disclosure. Share identities, contact information and sensitive findings only with people who need them for response. Do not publish screenshots or reconstruct a target’s relationships for awareness material.
For technical responders, the advisory contains detection material and investigation guidance. Unexpected use of a legitimate cloud or messaging service can warrant investigation in context; it is not enough on its own to establish CHOSEN BRICK infection. A filename or persistence entry is similarly a lead rather than a complete verdict.
BlackTree has previously reported on the risks of a work identity used on a personal device. The incidents are not connected. The shared operational question is where organisational security stops while a person’s exposure continues.
Here, the consequence is not only a compromised account. It can be a life made easier to observe. The response should protect the person behind the endpoint, not simply close the ticket that recorded a blocked download.
Sources
- UK NCSC, FBI and AIVD joint advisory on Iranian cyber targeting of dissidents, activists and journalists, published 15 September 2026.
- AIVD, warning about Iranian cyber actors using malware against dissidents, activists and journalists, published 15 September 2026.



Thank you for this article; the distinction that the malware’s additional-payload capability is not proof that it was used, and the reminder that support for targeted people should stay proportionate and respect their privacy, show a careful, responsible approach to reporting on this campaign.