Iranian hackers have been using a sophisticated Windows malware strain, known as CHOSEN BRICK, to spy on targets worldwide. The threat actor, believed to be linked to the Iranian government, has been targeting dissidents, activists, and journalists in the U.S., U.K., and Netherlands with a highly customized approach.
The attacks begin with social engineering messages sent via WhatsApp or Telegram, impersonating trusted contacts or technical support agents. These messages trick victims into opening malicious files disguised as legitimate applications, such as antivirus software or popular apps like Pictory or RunwayML. Once launched, these fake apps silently install CHOSEN BRICK in the background and secure persistence through Windows Registry Run keys.
CHOSEN BRICK is a highly capable piece of malware that can perform a range of actions on an infected device, including collecting system information, enumerating running processes, capturing screenshots, recording audio, stealing email content, and downloading additional payloads. The stolen data is then exfiltrated through Telegram or cloud services like VultrObjects and StorjShare.
The advisory notes that the Iranian government uses cyber activity to support the repression of individuals who are seen as a threat to the regime, including dissidents, activists, and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.
The use of CHOSEN BRICK malware is a stark reminder that social engineering attacks can be just as effective as zero-day exploits in compromising devices. The fact that these attacks are highly customized and tailored to specific targets makes them particularly difficult to detect.
Potential victims and organizations should inspect Registry Run entries for suspicious entries, search logs for indicators of compromise (IoCs) shared in the advisory, and monitor for unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies. By staying vigilant and taking proactive steps to secure their devices, individuals can reduce their risk of falling victim to these types of attacks.
In light of this threat, it is essential for organizations to review their security protocols and ensure that employees are aware of the risks associated with social engineering attacks. This includes implementing robust cybersecurity awareness training programs, regularly updating software and operating systems, and monitoring for suspicious activity on networks and devices. By taking a proactive approach to cybersecurity, individuals and organizations can better protect themselves against the growing threat of CHOSEN BRICK malware.
Source: Bleeping Computer — 2026-09-16