Western intelligence agencies have issued a warning regarding Iranian state actors using CHOSEN BRICK malware to target and spy on dissidents, journalists, and activists across multiple countries.
Key Points
- The UK’s NCSC, the FBI, and the Netherlands’ AIVD identified the campaign targeting individuals in their respective nations since early 2025.
- Attackers build rapport on WhatsApp and Telegram before tricking victims into downloading malicious files disguised as legitimate software like Norton Antivirus or RunwayML.
- CHOSEN BRICK infects Windows systems, using registry keys to survive reboots and adding exclusions to Microsoft Defender to evade detection.
- The malware enables operators to capture screenshots, record audio, steal browser data, and exfiltrate emails or contact lists from infected devices.
- Stolen information has been published on pro-Iranian leak sites and used to facilitate physical threats, including kidnapping and lethal operations against regime critics.