AUTO-UPDATED

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

Western intelligence agencies have issued a warning regarding Iranian state actors using CHOSEN BRICK malware to target and spy on dissidents, journalists, and activists across multiple countries.

Key Points

  • The UK’s NCSC, the FBI, and the Netherlands’ AIVD identified the campaign targeting individuals in their respective nations since early 2025.
  • Attackers build rapport on WhatsApp and Telegram before tricking victims into downloading malicious files disguised as legitimate software like Norton Antivirus or RunwayML.
  • CHOSEN BRICK infects Windows systems, using registry keys to survive reboots and adding exclusions to Microsoft Defender to evade detection.
  • The malware enables operators to capture screenshots, record audio, steal browser data, and exfiltrate emails or contact lists from infected devices.
  • Stolen information has been published on pro-Iranian leak sites and used to facilitate physical threats, including kidnapping and lethal operations against regime critics.

Why it Matters

This campaign highlights a significant escalation in how state-sponsored actors leverage social engineering to bypass corporate security by targeting personal devices. The use of sophisticated surveillance tools against private citizens underscores the growing risk to international activists and the potential for digital espionage to result in real-world physical harm.
Help Net Security Published by Sinisa Markovic
Read original