Skip to main content
Emerging ThreatsMalware & Ransomware

Iranian Hackers Deploy CHOSEN BRICK Malware to Spy on Global Targets

Modern office setting with laptop and papers, blurred background.

“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” one line in the joint advisory from U.S., U.K., and Dutch cybersecurity agencies, published with the FBI, bluntly states. The advisory lays out how a Windows malware strain named CHOSEN BRICK has been used to turn common communications apps and file lures into long-term spying tools against targets worldwide.

CHOSEN BRICK: capabilities exposed

The advisory details a full suite of espionage functions built into CHOSEN BRICK. Once installed, the malware can collect system information and enumerate running processes; capture screenshots; record audio through the microphone; steal email content and browser data for Telegram and WhatsApp; download additional payloads into "C:\Windows \SysWOW64"; delete files; and even wipe the entire host. The agencies say CHOSEN BRICK also establishes persistence via Windows Registry Run keys and adds Microsoft Defender exclusions to evade detection.

Delivery: social engineering through WhatsApp and Telegram

According to the advisory, attacks typically begin with social engineering messages sent over WhatsApp or Telegram that impersonate trusted contacts or technical support agents. Targets are encouraged to open files that masquerade as legitimate applications — examples listed in the advisory include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass — and are sometimes urged to launch them on personal devices to evade corporate security controls. The agencies also note that the threat actor has used medical-related lures in some cases.

These fake apps display interfaces that match the lure, all while silently installing CHOSEN BRICK in the background. The malware also connects to a unique Telegram bot that is matched to the victim’s ID and functions as command-and-control (C2), the advisory says.

Exfiltration and evasion: Telegram, cloud stores, and SOCKS5

Stolen data is extracted through several channels the advisory identifies by name. Exfiltration has used Telegram as well as cloud services such as VultrObjects and StorjShare. Newer CHOSEN BRICK variants route traffic through SOCKS5 proxies to conceal activity, and the advisory flags unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies as worthy of investigation. The combined techniques — Microsoft Defender exclusions, Registry persistence, Telegram-based C2 and proxying — create multiple layers intended to make detection and attribution harder.

Targets, consequences, and public exposure

The advisory says the threat actor has primarily targeted individuals in the U.S., U.K., and the Netherlands, and that the broader target set includes dissidents, activists, and journalists worldwide. The agencies warn that some of the data exfiltrated by CHOSEN BRICK has appeared on pro-Iranian leak sites, where publication serves both as harassment and as a mechanism that can increase the physical risk to those named. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime,” the advisory adds.

What this means for technologists, policymakers, and journalists

  • Technologists and security teams should inspect Registry Run entries for suspicious entries, search logs for the indicators of compromise (IoCs) the advisory shares, and investigate unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies.
  • Policymakers and law-enforcement partners must weigh the advisory’s account that exfiltration is not only intelligence collection but also part of harassment campaigns that elevate physical risk to targeted individuals, and consider coordination on protective measures for at-risk persons.
  • Journalists, dissidents, and activists should be wary of unsolicited messages over WhatsApp or Telegram that urge running apps on personal devices; the advisory explicitly notes the actor’s use of convincing app interfaces and pretexts that include technical support and medical cues to persuade victims to bypass corporate defenses.

The advisory provides a detailed operational picture: plausible lures, a Windows persistence mechanism, named cloud services and proxy tools used for exfiltration, and an established pattern of leaking stolen data publicly. For the people identified in those leaks, the advisory is not an abstract cyber-warning but an account of real-world exposure and increased physical risk. Agencies and defenders now have a set of concrete artifacts to hunt for; whether that hunting will prevent future harassment or escalation remains a question the alert leaves squarely to follow-up action.

Original advisory and reporting