Download Privacy Needle App

Type to search

Cybersecurity

Iranian State-Linked Hackers Use CHOSEN BRICK Malware to Target Dissidents

Share

Government agencies, including the FBI and the Dutch National Cyber Security Centre (NCSC), have issued a warning regarding a Windows malware strain named CHOSEN BRICK. The malware is being deployed by Iranian state-linked threat actors to conduct espionage against dissidents, activists, and journalists globally.

The threat actors primarily target individuals in the United States, the United Kingdom, and the Netherlands. Intelligence agencies have noted that the cyber activity is likely intended to support the repression of individuals perceived as threats to the Iranian regime.

Social Engineering and Infection Vectors

The attack typically begins through social engineering messages sent via WhatsApp or Telegram. Attackers impersonate trusted contacts or technical support agents to trick victims into opening malicious files.

These files are often disguised as legitimate applications, such as Norton Antivirus, Adobe Flash Player, Telegram, or various AI-related tools like RunwayML. In some instances, hackers have even utilised medical-related lures, such as documents claiming to be MRI scans, to entice targets into running the software on their personal devices to bypass corporate security controls.

Once executed, the malicious files present a convincing interface that matches the initial lure while silently installing CHOSEN BRICK in the background. The malware secures persistence by modifying Windows Registry Run keys and frequently adds exclusions to Microsoft Defender to evade detection.

Espionage and Data Exfiltration

CHOSEN BRICK is designed for comprehensive data theft and surveillance. Once a system is compromised, the malware can perform the following actions:

  • Collect system information and enumerate running processes;
  • Capture screenshots and record audio via the microphone;
  • Steal email content and browser data from Telegram and WhatsApp;
  • Download additional payloads to system directories;
  • Delete files or wipe the entire host system.

Stolen data is exfiltrated through Telegram bots or cloud services such as VultrObjects and StorjShare. Newer variants of the malware have been observed routing traffic through SOCKS5 proxies to conceal the movement of stolen information.

Security agencies have warned that stolen data is sometimes published on pro-Iranian leak sites. This not only exposes private communications but also increases the physical security risks for dissidents living abroad.

Mitigation and Detection

To defend against CHOSEN BRICK, organisations and individuals should inspect Windows Registry Run entries for any suspicious or unknown applications. Security teams should also investigate unexpected connections to the Telegram API or cloud storage providers including Backblaze B2, VultrObjects, and StorjShare.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.