Key Takeaways
- New spyware called Chosen Brick uses Telegram to spy on Windows devices
- Authorities say hackers pose as trusted contacts to deliver fake files
- The Chosen Brick malware can capture screenshots, audio, and personal messages
Security agencies from the United States, United Kingdom, and Netherlands have warned about a spyware campaign that uses Telegram infrastructure to monitor journalists, activists, and other individuals abroad. The malware, called Chosen Brick, targets Windows computers and has been active since at least 2025.
How the Malware Spreads
According to the joint advisory, attackers first research their targets and then reach out through encrypted messaging apps like WhatsApp and Telegram. They pose as trusted contacts or technical support staff to build a relationship with the victim over time.
Once trust is established, the attackers send a disguised file designed to look legitimate. These have included fake versions of popular apps such as antivirus software, photo editing tools, and even a set of fake medical scan results.
The Chosen Brick malware also tends to appear when targets switch from secured work devices to personal computers, where fewer protections may be in place. Security researchers say this shift can create new opportunities for attackers even after an attempt fails on a monitored device.
What the Spyware Can Do
Once installed, Chosen Brick connects to a unique messaging channel for each victim, helping the attackers keep track of individual targets separately. The malware can survive computer restarts and remains active in the background.
The Chosen Brick malware can take screenshots, record audio through the microphone, and collect emails, messages, and files stored on the device. It can also download additional harmful programs or remove files from the infected system.
Authorities note that stolen information, including contact lists and location details, can reveal a person’s daily routine and social connections. Such data can expose not just the original target, but also people connected to them, such as sources or collaborators.
Protecting Against the Threat
Security agencies recommend that people avoid downloading files sent through unsolicited messages, even when they appear to come from familiar contacts. Verifying a sender’s identity through a separate channel before opening any attachment can reduce risk.
Keeping software updated and downloading apps only from official sources also helps block common Chosen Brick malware infection methods. Officials further suggest enabling strong authentication measures on important accounts.
People who believe they may be targeted by this type of surveillance can seek additional guidance from national cybersecurity authorities. Awareness of common tactics, such as impersonation and slow relationship-building before an attack, remains one of the most effective defenses.
The advisory adds to a wider pattern of Chosen Brick malware and digital surveillance campaigns affecting journalists and civil society groups worldwide. Security researchers continue to track new variants of this malware family to help protect potential targets.
Visit CyberPro Magazine to read more.




