Iranian Hackers Use Windows Malware to Spy on Targets Worldwide
A sophisticated cyberattack campaign has been uncovered, with Iranian state-linked hackers using a Windows malware strain called CHOSEN BRICK to spy on dissidents, activists, and journalists worldwide. The malware, which features data theft and espionage capabilities, has been used to target individuals in the U.S., U.K., and the Netherlands.
The attackers use social engineering tactics to trick their victims into opening malicious files disguised as legitimate applications, often suggesting they launch them on personal devices to bypass corporate security blocks. Once launched, the malware installs itself silently in the background, securing persistence through Windows Registry Run keys and adding Microsoft Defender exclusions to evade detection. The stolen data is then exfiltrated through Telegram or cloud services like VultrObjects and StorjShare.
CHOSEN BRICK’s capabilities include collecting system information, enumerating running processes, capturing screenshots, recording audio, stealing email content, and downloading additional payloads. Newer variants of the malware route traffic through SOCKS5 proxies to conceal the activity, making it harder for security professionals to detect. The stolen data sometimes ends up on pro-Iranian leak sites, serving as a form of harassment and increasing the physical risk for dissidents abroad.
The government agencies warn that Iran almost certainly uses cyberactivity to support the repression of individuals who are seen as a threat to the regime. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime. This campaign highlights the ongoing cat-and-mouse game between nation-state hackers and their targets.
The advisory notes that potential victims and organizations should inspect Registry Run entries for suspicious entries and search logs for indicators of compromise (IoCs) shared in the advisory. Unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies should also be investigated as suspicious.
As we continue to navigate the complex world of nation-state hacking, it’s essential for organizations and individuals to stay vigilant and take proactive measures to protect themselves. This includes staying informed about emerging threats, implementing robust security protocols, and regularly monitoring system logs for signs of compromise. By doing so, we can better defend against these sophisticated attacks and safeguard our online activities.
To protect yourself from CHOSEN BRICK and similar malware, it’s crucial to maintain up-to-date antivirus software, use strong passwords and enable two-factor authentication, avoid opening suspicious files or links, and regularly back up your data. By taking these precautions, you can significantly reduce the risk of falling victim to this type of attack.
Source: Bleeping Computer — 2026-09-16