Iranian State-Linked Hackers Use CHOSEN BRICK Malware to Target Dissidents
Share
Government agencies, including the FBI and the Dutch National Cyber Security Centre (NCSC), have issued a warning regarding a Windows malware strain named CHOSEN BRICK. The malware is being deployed by Iranian state-linked threat actors to conduct espionage against dissidents, activists, and journalists globally.
The threat actors primarily target individuals in the United States, the United Kingdom, and the Netherlands. Intelligence agencies have noted that the cyber activity is likely intended to support the repression of individuals perceived as threats to the Iranian regime.
Social Engineering and Infection Vectors
The attack typically begins through social engineering messages sent via WhatsApp or Telegram. Attackers impersonate trusted contacts or technical support agents to trick victims into opening malicious files.
These files are often disguised as legitimate applications, such as Norton Antivirus, Adobe Flash Player, Telegram, or various AI-related tools like RunwayML. In some instances, hackers have even utilised medical-related lures, such as documents claiming to be MRI scans, to entice targets into running the software on their personal devices to bypass corporate security controls.
Once executed, the malicious files present a convincing interface that matches the initial lure while silently installing CHOSEN BRICK in the background. The malware secures persistence by modifying Windows Registry Run keys and frequently adds exclusions to Microsoft Defender to evade detection.
Espionage and Data Exfiltration
CHOSEN BRICK is designed for comprehensive data theft and surveillance. Once a system is compromised, the malware can perform the following actions:
- Collect system information and enumerate running processes;
- Capture screenshots and record audio via the microphone;
- Steal email content and browser data from Telegram and WhatsApp;
- Download additional payloads to system directories;
- Delete files or wipe the entire host system.
Stolen data is exfiltrated through Telegram bots or cloud services such as VultrObjects and StorjShare. Newer variants of the malware have been observed routing traffic through SOCKS5 proxies to conceal the movement of stolen information.
Security agencies have warned that stolen data is sometimes published on pro-Iranian leak sites. This not only exposes private communications but also increases the physical security risks for dissidents living abroad.
Mitigation and Detection
To defend against CHOSEN BRICK, organisations and individuals should inspect Windows Registry Run entries for any suspicious or unknown applications. Security teams should also investigate unexpected connections to the Telegram API or cloud storage providers including Backblaze B2, VultrObjects, and StorjShare.




Leave a Reply