The advice “use a password manager” assumes you got the password manager from the password manager. In a joint advisory published September 15, the UK's NCSC, the FBI and the Netherlands' AIVD describe malware sent to dissidents, activists and journalists disguised as ordinary software—including a fake KeePass installer. NCSC tracks it as CHOSEN BRICK; the FBI calls it HEAVYGRAM.
For a product about handling secrets, this is the uncomfortable case. The victim is doing the right things. They are careful, they use security tools, they are aware they are a target. The attack succeeds because it arrives inside that awareness rather than against it.
What is confirmed
The three agencies attribute the activity to Iranian state cyber actors; reporting by The Hacker News, citing the agencies, points specifically to Iran's Ministry of Intelligence and Security. The advisory describes targeting of dissidents, activists and journalists, with victims in the UK, the US and the Netherlands as well as elsewhere.
The delivery method is patient social engineering rather than mass phishing. Operators approach targets on messaging platforms, impersonating a trusted contact or platform support staff, and build rapport before sending anything. The payload is then disguised as a legitimate application—NCSC lists Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass—or as a plausible document such as MRI scan results.
Once installed, the agencies describe capabilities that include taking screenshots, capturing audio through the microphone, copying Telegram and WhatsApp data from browsers, stealing saved passwords and email content, enumerating running processes, downloading further malware, and deleting files. NCSC notes that at least one version can wipe a system. Command and control runs through Telegram bots, with a separate bot per victim so data does not mix, and NCSC describes exfiltration through commercial cloud object storage services. Reporting places the campaign's origins in autumn 2023, with documented targeting since at least 2025.
The advisory is blunt about why this matters beyond data loss: it notes that Iranian intelligence has plotted to kidnap or conduct lethal operations against individuals. This is surveillance with physical consequences attached.
What remains unknown
The public advisory does not establish how many people were successfully compromised, which specific individuals were targeted, or what was done with material that was taken. Attribution to a state intelligence service is the assessment of three government agencies; it is not something a reader can independently verify. The presence of your country in the victim list does not tell you whether you personally were approached.
The specific lesson: security tools are a lure
Most malware impersonates something boring—an invoice, a delivery notice, a CV. This campaign impersonates the categories a security-conscious person actively wants: antivirus, an encrypted messenger, a password manager. That inverts the usual mental model. Wanting the software is what makes the lure work.
The rule that follows is narrow and absolute, and it is worth stating as a rule rather than a tendency:
- Install security software only from the vendor's own site or the platform's official store, reached by typing the address yourself or using a bookmark you created earlier. Never from a link or attachment someone sent you, no matter how well you know them and no matter how helpful the conversation has been.
- A helpful contact is not a verified contact. The rapport is the attack. Accounts get compromised and impersonated; a real relationship in a messaging app is not proof of who is typing today.
- Treat “support” contact that comes to you as hostile by default. Platform support does not open a chat to send you an installer.
- Be wary of files that exploit concern rather than greed. Medical results, legal documents and safety warnings are effective precisely because they bypass the scepticism a financial lure would trigger.
If you think you were targeted
The capability list matters here, because it determines what recovery has to assume. If this malware ran, then saved browser passwords, messenger session data and email content should all be treated as taken.
- Do not start recovery on the affected device. New passwords typed on a machine that captures screenshots and keystrokes are compromised before they are saved. Use a different, clean device.
- Assume messenger sessions are stolen, not just passwords. Changing a password does not end an existing session. Sign out all devices and re-authenticate in Telegram, WhatsApp, email and anything federated to them.
- Move to phishing-resistant multi-factor authentication—a hardware security key or passkey—on the accounts that matter most. This is the agencies' own recommendation for organisations and it applies equally to individuals at elevated risk.
- Do not coordinate recovery in the channel that was used to reach you. If the approach came through a messaging platform, that platform is the wrong place to discuss what you are changing or to receive replacement credentials.
- Get help from a support organisation, not a stranger. Press-freedom and digital-rights organisations run dedicated helplines for exactly this situation. NCSC also publishes protective guidance for individuals at heightened risk.
For organisations that employ or work with journalists and activists, the agencies recommend phishing-resistant MFA, application allowlisting, endpoint monitoring, email security scanning, and hunting through logs for the published indicators. Worth adding: decide now how you would reach a compromised colleague out of band, because the moment you need that answer is the moment their usual channels cannot be trusted.
Where Secretus fits—and where it does not
Secretus can reduce plaintext exposure when someone must pass a small, temporary value—a recovery code, a replacement credential—to a person they have already verified through a separate route, without leaving it sitting in a mailbox or chat history that may already be readable by someone else.
It does not help with the central problem in this advisory. It cannot tell you whether a device is infected, cannot verify that the person on the other end is who they claim to be, and cannot make a value safe if it is opened on a compromised machine—anything decrypted in a browser on an infected endpoint is visible to whatever is watching that browser. If you are at elevated risk, the clean device and the out-of-band verification come first; a one-time channel is only useful after those.
