CHOSEN BRICK / HEAVYGRAM: Iranian MOIS spyware targeting journalists and dissidents, Telegram C2, fake Norton/KeePass lures, FBI-NCSC-AIVD joint advisory, physical threat context included      Google Pixel September update: 110 CVEs including CVE-2026-58704 privilege escalation zero-day confirmed exploited in targeted attacks, update Pixel devices now      Admin Menu Editor Pro supply chain: maintainer site compromised, malicious plugin updates pushed to 200+ WordPress customers, hidden admin account created silently      CHOSEN BRICK / HEAVYGRAM: Iranian MOIS spyware targeting journalists and dissidents, Telegram C2, fake Norton/KeePass lures, FBI-NCSC-AIVD joint advisory, physical threat context included      Google Pixel September update: 110 CVEs including CVE-2026-58704 privilege escalation zero-day confirmed exploited in targeted attacks, update Pixel devices now      Admin Menu Editor Pro supply chain: maintainer site compromised, malicious plugin updates pushed to 200+ WordPress customers, hidden admin account created silently     
CyberSipTM
Intelligence without the noise
Issue No. 132
September 17, 2026
3 items · past 24h
<5 min read
Today's picture

The FBI, UK's National Cyber Security Centre, and Netherlands' AIVD jointly exposed CHOSEN BRICK, a Windows surveillance implant Iran's Ministry of Intelligence and Security has deployed against dissidents, journalists, and activists in the UK, US, and Netherlands since at least 2025, delivered via social engineering on WhatsApp and Telegram using files disguised as Norton Antivirus, KeePass, or medical records, capable of harvesting contacts, emails, screenshots, and audio while using Telegram bots for command-and-control, with the advisory explicitly noting that Iranian intelligence services have in some cases plotted to kidnap or conduct lethal operations against targeted individuals. Google released September security patches for Pixel devices covering 110 vulnerabilities, including CVE-2026-58704, a privilege escalation zero-day confirmed exploited in targeted attacks. A threat actor compromised the website of the Admin Menu Editor Pro WordPress plugin maintainer and pushed trojanized updates to more than 200 paying customers, silently installing a hidden administrator account on each affected site.

Today's intelligence
3 items
01 HighIran MOISCHOSEN BRICK / HEAVYGRAM
FBI, NCSC, and AIVD jointly named an Iranian MOIS spyware targeting journalists and dissidents via fake KeePass files and Telegram bots — with a physical threat warning attached
CHOSEN BRICK is a Windows-only implant attributed to Iran's Ministry of Intelligence and Security. Operators spend days building rapport with targets on WhatsApp and Telegram before delivering the payload inside a file disguised as Norton Antivirus, KeePass, Pictory, or in one documented case a fake MRI scan. Once installed it harvests contacts, emails, screenshots, and audio, and can wipe the device. The advisory is unusually candid: the same Iranian actors have in some cases plotted to kidnap or kill targeted individuals abroad.
NamesCHOSEN BRICK
(NCSC)
HEAVYGRAM (FBI)
Same malware
ActorIranian MOIS
(Ministry of
Intelligence &
Security)
TargetsDissidents, activists
journalists
UK, US, Netherlands
since 2025
DeliveryWhatsApp / Telegram
social engineering
Fake Norton, KeePass
Telegram, Pictory
MRI scans
CapabilitiesContacts, emails
Screenshots, audio
Browser tokens
Cloud exfil
Device wipe module
Telegram C2
On September 15, 2026, the UK's NCSC, the FBI, and the Netherlands' AIVD jointly published an advisory naming CHOSEN BRICK, a Windows surveillance implant attributed to Iran's Ministry of Intelligence and Security. The FBI tracks the same malware family under the name HEAVYGRAM; the agencies do not formally declare the two names exact aliases, and analysts should use both in reporting. The campaign has targeted dissidents, activists, and journalists in the UK, US, and Netherlands since at least 2025, with the underlying operation dating to autumn 2023 according to the FBI. The attack chain begins with extensive reconnaissance: operators study the target's network and contacts before approaching on WhatsApp or Telegram, impersonating someone the target already knows or a credible organization. They spend days building rapport before sending the payload. Documented lures include files impersonating Norton Antivirus, Adobe Flash Player, KeePass, Telegram, Pictory, RunwayML, and in one case a fake MRI scan showing a disc herniation tailored to a target known to have a back injury. Once a target opens the file, a decoy screen appears while CHOSEN BRICK installs silently. The malware persists via a HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry entry and immediately begins harvesting contacts, email inboxes, social media messages, and browser authentication tokens. It captures screenshots, activates the microphone for audio recording, and routes exfiltration through cloud object storage services including Vultr, Backblaze, and Storj. Each victim is assigned a unique Telegram bot for command-and-control. CHOSEN BRICK also adds exclusions to Microsoft Defender to evade detection. A data-wiping module is documented in the advisory. The NCSC advisory includes an unusually explicit statement: "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally who they perceive as enemies of the regime."
The CHOSEN BRICK advisory is notable for what it connects: the cyber surveillance campaign is not self-contained. Intelligence agencies in three countries are explicitly linking the same MOIS apparatus that deploys the malware to physical threat planning against the same targets. For journalists, activists, and dissidents with any connection to Iran-related reporting or advocacy, this means the digital risk and the physical risk come from the same actor. For security teams and organizations that employ or work with individuals in those categories, the advisory changes the threat model: detecting CHOSEN BRICK installation is not only a cyber incident but potentially an early warning of an escalating threat to the individual. The tradecraft of spending days building rapport before delivery makes this campaign resistant to standard phishing awareness training, which focuses on unsolicited messages rather than extended trusted relationships.
The advisory documents a specific operational technique worth flagging to at-risk individuals and their security contacts: CHOSEN BRICK operators reportedly prefer to approach the target's work device first, then steer the conversation to a personal device specifically to move outside corporate security controls. The transition from a work conversation to "let's continue this on my personal WhatsApp" is not incidental. It is the designed step that moves the delivery outside the perimeter where endpoint detection, email scanning, and DLP controls operate. At-risk individuals should apply the same skepticism to trusted-feeling contacts requesting file transfers on personal messaging apps as they would to unsolicited phishing, particularly when the file is something personal or medical in nature.
  • Organizations employing journalists, human rights workers, researchers, or advocates who cover Iran-related topics should brief those individuals on the CHOSEN BRICK advisory and its indicators. The joint FBI/NCSC/AIVD IoC release includes file hashes, registry persistence locations, and network indicators for cloud exfiltration traffic. Review endpoint telemetry for the HKCU Run key persistence entries, Defender exclusion modifications, and outbound connections to Vultr, Backblaze, and Storj from endpoints that do not normally use those services.
  • At-risk individuals should treat any inbound file from a WhatsApp or Telegram contact as suspicious if the file was unexpected, arrived after an unusually attentive outreach period, or the sender pivoted the conversation from a professional channel to a personal messaging app before sending it. Do not open files from messaging apps on a primary work or personal device; use an isolated analysis environment or submit the file to a malware sandbox before opening. Report any suspected contact to the organizations in the advisory: UK NCSC's report form, FBI's IC3, or Netherlands' AIVD.
Spend days gaining the target's trust. Send a fake MRI scan tailored to their known medical history. Wait for them to open it on their personal phone away from corporate controls. Harvest everything. The same MOIS apparatus has plotted to kill some of the people it surveils this way. This is not a phishing campaign. It is the digital component of a physical repression program. Journalists and dissidents covering Iran need to see this advisory.
02 HighGoogle PixelCVE-2026-58704
Google patched a Pixel privilege escalation zero-day confirmed exploited in targeted attacks — update all Pixel devices now
Google's September 2026 Pixel security bulletin covers 110 vulnerabilities including CVE-2026-58704, a privilege escalation flaw Google flags as under limited, targeted exploitation. The nature of targeted exploitation on a Pixel zero-day is consistent with commercial spyware or nation-state tooling. Google announced the patch September 15. Apply the September security level immediately on all managed and personal Pixel devices.
Zero-dayCVE-2026-58704
Privilege escalation
Targeted exploitation
confirmed
PatchSeptember 2026
Pixel security
bulletin
110 CVEs total
Update to2026-09-05 or
2026-09-01
security patch
level on Pixel
PatternTargeted exploitation
consistent with
spyware or
nation-state use
Google published its September 2026 Pixel security bulletin on September 15, addressing 110 vulnerabilities across the Pixel device line. CVE-2026-58704 is a privilege escalation vulnerability that Google notes is under exploitation in targeted attacks. Google's use of "limited, targeted exploitation" in its Pixel advisories has historically indicated commercial spyware or nation-state tooling rather than broad criminal campaigns; the same language accompanied the Pixel zero-days associated with Pegasus and Predator spyware use in prior years. The September bulletin covers two security patch levels: the 2026-09-01 level addresses a core set of vulnerabilities, and the 2026-09-05 level includes all of the 2026-09-01 fixes plus device-specific and kernel component patches. Pixel devices receive security updates directly from Google and should apply the September update as soon as it is available in Settings.
A Pixel privilege escalation zero-day under targeted exploitation, disclosed in the same week as the CHOSEN BRICK advisory, is a reminder that mobile device security and surveillance campaign infrastructure are often linked. Commercial spyware vendors develop Pixel and Android zero-days as initial access capabilities. Nation-state actors acquire or develop them for targeted campaigns. "Limited targeted exploitation" does not mean low risk for the specific population being targeted; it means broad criminal deployment has not been observed, but the individuals being targeted with this exploit may face a significant threat. Update Pixel devices immediately; the update removes a known capability from whatever actor is currently using it.
  • Apply the September 2026 Pixel security update to all Pixel devices immediately via Settings > Security & privacy > System & updates > Security update. Confirm the security patch level shows 2026-09-05 after update and restart. For enterprise MDM-managed Pixel fleets, push the update via your device management console rather than waiting for automatic rollout.
Privilege escalation zero-day. Targeted exploitation confirmed. The "limited, targeted" language on a Pixel zero-day historically means spyware. Update Pixel devices now. This week's CHOSEN BRICK advisory and this Pixel zero-day are not the same campaign, but they describe the same threat category: sophisticated actors targeting specific individuals with mobile and desktop surveillance tooling.
03 HighWordPressSupply Chain
Attackers compromised the Admin Menu Editor Pro maintainer website and pushed trojanized plugin updates to 200+ paying customers, creating silent hidden admin accounts
The plugin maintainer's website was compromised. The attacker pushed malicious update packages through the legitimate update channel to customers who had purchased the premium plugin. Each affected site received an update that created a hidden administrator account with an attacker-controlled password. The attack exploited the trust relationship between a plugin author and their paying customer base rather than any vulnerability in WordPress itself.
PluginAdmin Menu Editor Pro
Premium WordPress
plugin
VectorMaintainer website
compromised, pushed
malicious update
Customers hit200+ paying
customers
PayloadHidden WordPress
admin account
created silently
Not affectedFree version on
WordPress.org
repository
An attacker compromised the website of the developer behind Admin Menu Editor Pro, a premium WordPress plugin sold directly to customers outside the WordPress.org repository. The attacker modified the update packages distributed through the plugin's own update mechanism and pushed the trojanized version to customers who had the plugin installed and auto-updates enabled. More than 200 paying customers received the malicious update. The payload created a hidden WordPress administrator account with attacker-controlled credentials that does not appear in the standard WordPress admin user list. The free version of Admin Menu Editor, distributed through the WordPress.org plugin repository, was not affected because the WordPress.org repository has its own distribution infrastructure separate from the plugin author's direct sales site. The plugin author discovered the compromise and has notified affected customers.
This incident is structurally identical to software supply chain attacks against commercial software vendors: compromise the distribution infrastructure, push malicious updates through the channel customers trust for legitimate software delivery. The WordPress plugin ecosystem's premium plugin model, where paid plugins are often distributed directly from the developer's own website rather than through WordPress.org's reviewed repository, creates a supply chain dependency on each developer's own hosting and update infrastructure security. A customer who purchased a plugin in good faith and enabled auto-updates had no way to detect this attack through standard WordPress security practices, because the malicious code arrived through the same trusted channel as legitimate updates.
  • Audit WordPress user accounts on any site running Admin Menu Editor Pro to identify hidden administrator accounts created after the plugin update. In WordPress, navigate to Users > All Users and check for accounts that are not recognizable as legitimate administrators, paying particular attention to accounts with administrator role that were created in the past week. Remove any unauthorized accounts immediately and rotate the passwords of all legitimate administrator accounts on affected sites.
  • For organizations managing multiple WordPress installations, this incident justifies auditing all premium plugins distributed outside the WordPress.org repository for recent update history. For any premium plugin that auto-updated within the past week, verify the update integrity and review what changed. Limiting auto-updates on premium plugins to a staged approval workflow, rather than automatic silent installation, is a policy control that would have allowed detection before installation in this case.
The attacker hit the developer's website, not the plugin itself. The malicious update arrived through the same channel as every legitimate update. 200+ customers got a hidden admin account they did not know existed. Check your WordPress user list on any site running this plugin. Review premium plugin auto-update policies.
Cross-source standouts
01
CHOSEN BRICK and the limits of phishing awareness training: why rapport-based delivery defeats standard defenses
Standard phishing awareness training teaches people to be suspicious of unsolicited messages, unfamiliar senders, and unexpected file attachments. CHOSEN BRICK operators invert all three preconditions. The message is not unsolicited; it arrives in an ongoing conversation with someone the target already knows, or believes they know. The sender is not unfamiliar; extensive reconnaissance means the operator knows the target's contacts, professional relationships, and in documented cases their medical history. The attachment is not unexpected; the conversation has been steered toward a reason for sending it. The NCSC's advisory notes that operators specifically steer conversations from work devices to personal ones before delivering the payload, explicitly to move outside corporate security controls. This combination means that the cognitive signals that make phishing detectable: unexpectedness, unfamiliarity, urgency, are systematically removed before delivery. The operational defense against rapport-based delivery is not awareness training about unexpected messages; it is a standing policy for at-risk individuals that no file should be opened from a messaging app on a primary device regardless of how trusted the sender feels, combined with an established reporting channel for exactly this kind of escalating contact.
02
Premium plugin supply chain risk: the WordPress ecosystem's commercial distribution gap
The WordPress.org plugin repository applies a review and integrity process to free plugins that makes the kind of supply chain attack seen in the Admin Menu Editor Pro incident difficult to execute through that channel. Premium plugins distributed directly by developers through their own websites do not have that backstop. Each premium plugin is effectively its own software supply chain, dependent on the security of the developer's website, update server, and code signing practices. A WordPress site administrator who installs premium plugins from developer websites has implicitly accepted a supply chain dependency on each of those developers' own infrastructure security, a dependency most WordPress operators do not explicitly evaluate. This is not a criticism of the premium plugin model, which offers capabilities that free plugins cannot economically support. It is a structural observation: the trust model for premium plugin distribution is materially different from the trust model for WordPress.org repository plugins, and the security practices appropriate to each differ accordingly.
Still watching
Days 3–7+
Cisco Secure Email Gateway CVE-2026-76461 (Issue 131 · CVSS 9.8, root RCE via crafted email, CISA KEV) — patch AsyncOS immediately. If running vulnerable before patch, review gateway logs for unexpected outbound connections, new accounts, or process execution events.
Day 2
GitLab CVE-2026-85706 (Issue 129 · max-severity path traversal, mass exploitation active) — patch all self-managed instances. Hunt POST to /api/v4/projects/{id}/repository/commits/ with file.path parameter. CVE-2026-19478 active simultaneously; verify both independently.
Day 5
ShieldCrash (ShieldBreak bypass) (Issue 126 · Nightmare Eclipse, no CVE, SYSTEM file read on latest patched Windows) — ShieldBreak CVE-2026-69414 patched. ShieldCrash unpatched. Monitor MSRC. Behavioral detection for the series must remain active.
Day 7+
SAP OVERPASS CVE-2026-44756 (Issue 126 · CVSS 10.0, unauthenticated SAP kernel EPP RCE) — apply patch per SAP Note 3500180. Restrict EPP endpoint to trusted networks. Still no confirmed exploitation — the window before first exploitation on a CVSS 10.0 SAP flaw is historically short.
Day 7+