Iran has allegedly been using malicious apps that impersonate cybersecurity products such as Norton Antivirus and the password manager KeePass to secretly infect victims with Windows-based spyware.
On Tuesday, the FBI joined the UK to alert the public about the threat, which has been traced to Iranian state-sponsored hackers attempting to target dissidents, activists, and journalists. The FBI’s advisory notes that Iranian hackers will first try to build a rapport with their targets via social messaging apps, posing as IT customer support. In other cases, they will pretend to be a known contact.
“The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target,” the FBI added. The AI video creation apps Pictory and RunwayML have been used as bait, in addition to Norton Antivirus, KeePass, the messaging app Telegram, and Adobe Flash Player. In other cases, the Iranian hackers also used a fake MRI test result to phish their targets.
(Credit: UK NCSC)
The malicious bait has been designed to download spyware called “Chosen Brick,” which surprisingly targets desktop PCs, rather than mobile phones. “In all observed instances, the malware has been exclusively targeted at the Windows operating system,” the FBI added.
The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says.
Recommended by Our Editors
The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said.
The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague about how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly,” and to avoid downloading apps from unofficial sources.
About Our Expert

Michael Kan
Principal Reporter
Experience
I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.
Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.
Click Here For The Original Source.
