Cybersecurity

Iranian Hackers Use CHOSEN BRICK Windows Malware to Spy on Targets

Government agencies across the globe, led by joint findings from the United States Federal Bureau of Investigation (FBI) and the United Kingdom’s National Cyber Security Centre (NCSC), have issued an urgent global security advisory regarding a sophisticated cyber espionage campaign orchestrated by state-sponsored Iranian threat actors. The campaign utilizes a previously undocumented, highly targeted Windows malware strain designated as CHOSEN BRICK. Designed specifically for deep surveillance and comprehensive data harvesting, this malicious tool is actively being deployed against international dissidents, political activists, journalists, and human rights defenders residing primarily in the United States, the United Kingdom, and the Netherlands.

The sophisticated nature of the CHOSEN BRICK campaign underscores a broader, deeply concerning escalation in transnational repression. Rather than focusing on traditional corporate espionage, intellectual property theft, or financial disruption, these Iranian state-backed operators are leveraging advanced cyber capabilities to silence, intimidate, and monitor critical voices operating safely outside of Iran’s borders. Security analysts emphasize that the integration of modern obfuscation techniques, trusted communication platforms, and convincing social engineering pretexts highlights the evolving adaptability of nation-state actors in targeting vulnerable populations.

An Anatomy of the CHOSEN BRICK Malware Framework

CHOSEN BRICK is a modular, feature-rich espionage tool written specifically to compromise Microsoft Windows operating systems. Once a system is successfully breached, the malware establishes persistent access and quietly initiates a wide array of reconnaissance and data-collection protocols. Among its core capabilities, CHOSEN BRICK is engineered to vacuum up sensitive personal data, intercept communications across encrypted messaging applications such as Telegram and WhatsApp, capture live screenshots of the victim’s desktop environment, and even record ambient audio through the host machine’s microphone.

To maintain operational longevity and avoid immediate administrative detection, the malware utilizes the Windows Registry Run keys to achieve persistence, ensuring that it automatically executes every time the infected machine reboots. Furthermore, CHOSEN BRICK incorporates defensive evasion routines by dynamically modifying or adding exclusions to Microsoft Defender, effectively blinding built-in security software to its presence and subsequent malicious activities.

Command-and-control (C2) communication is handled through creative, unorthodox channels. Rather than relying solely on traditional hardcoded IP addresses or standard web servers, the malware leverages unique Telegram bots mapped directly to individual victim identification numbers. This architecture allows operators to issue instructions and receive updates seamlessly while blending malicious traffic with legitimate application traffic. For data exfiltration, the malware uploads harvested logs, media files, and communications through Telegram channels or decentralized cloud storage providers like VultrObjects and StorjShare. More recent iterations of CHOSEN BRICK have introduced advanced proxy routing capabilities, channeling data through SOCKS5 proxies—such as IPRoyal and LightningProxies—to obscure the origin of the traffic and complicate attribution efforts by incident responders.

See also  Twitter Under Fire: Whistleblower Alleges Egregious Security Lapses and National Security Risks

Sophisticated Social Engineering and Personalized Lures

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

The operational success of the CHOSEN BRICK campaign relies heavily on precision-crafted social engineering tactics rather than zero-day software exploits. Threat actors invest significant time in reconnaissance, identifying targets’ personal networks, professional interests, and daily routines before initiating contact.

Initial contact is typically established through mainstream, trusted communication platforms like WhatsApp or Telegram. The hackers routinely impersonate trusted personal contacts, colleagues, civil rights organizations, or technical support representatives to lower the victim’s guard. Once trust is established, the victims are enticed into downloading and executing malicious payloads disguised as legitimate, popular software applications.

The spectrum of application lures utilized by the threat actors is remarkably broad, designed to cater to the specific profile of the victim. Disguised binaries have mimicked productivity tools like Pictory and RunwayML, widely used security software like Norton Antivirus, communication utilities like Telegram, media runtimes like Adobe Flash Player, and password managers like KeePass. In instances where targets proved skeptical or where a more urgent pretext was required, the hackers adapted their strategies to deploy highly personal or medical-related lures. Notably, investigative reports revealed that threat actors utilized fake medical documents, including realistic MRI scan files, to trick individuals into opening the malicious attachments.

To circumvent standard corporate security baselines—which often trigger alerts when software is downloaded on enterprise networks—the operators frequently instructed victims to launch the applications on their personal, unsecured home computers or laptops. Upon execution, these rogue applications display fully functional, highly convincing user interfaces that mimic the legitimate software they claim to be, effectively masking the malicious background installation of CHOSEN BRICK.

The Broader Context of Transnational Repression

The deployment of CHOSEN BRICK is not an isolated incident, but rather part of a documented, long-term strategy by Iranian intelligence services to target perceived enemies of the regime beyond Iran’s borders. According to security assessments and intelligence sharing among Western governments, Tehran increasingly relies on a blend of cyber operations and physical harassment to suppress dissent.

Historically, state-backed Iranian threat groups have engaged in doxing campaigns, publishing stolen private communications, personal documents, and intimate details on pro-Iranian leak sites. This tactic serves a dual purpose: it publicly humiliates dissidents and creates an environment of pervasive fear, effectively chilling free expression within diaspora communities. More alarmingly, government agencies note that in several documented historical instances, cyber espionage operations conducted by Iranian intelligence have directly preceded physical surveillance, kidnapping plots, or lethal operations directed at prominent critics living abroad.

By weaponizing malware like CHOSEN BRICK, the regime aims to map out entire social graphs, uncover underground opposition networks, and identify sources who leak information out of Iran to international journalists. The psychological toll on the victims is profound, as the breach of private chats on Telegram and WhatsApp strips away their last remaining safe havens for secure communication.

See also  Java Ecosystem Flourishes with JDK 27 Schedule Finalization, Critical Security Updates, and Advancements Across Key Projects
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Indicators of Compromise and Defensive Recommendations

In response to the growing wave of attacks, the NCSC, the FBI, and allied cybersecurity authorities have published detailed indicators of compromise (IoCs) to help at-risk individuals and organizations detect and neutralize CHOSEN BRICK infections. Cybersecurity professionals recommend that potential targets—particularly journalists, activists, human rights defenders, and Iranian diaspora communities—perform thorough audits of their computing environments.

Key defensive measures and investigative steps include:

  • Inspecting Windows Registry Run keys (HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun and corresponding machine-wide keys) for unauthorized, unfamiliar, or recently modified startup entries.
  • Reviewing system logs and endpoint detection telemetry for anomalous processes executing out of temporary directories or application folders associated with the aforementioned software lures.
  • Monitoring network traffic for unexpected, unauthorized outbound connections to the Telegram API, Backblaze B2 storage endpoints, VultrObjects, StorjShare, or third-party proxy services such as IPRoyal and LightningProxies.
  • Verifying that endpoint security solutions are fully updated and that security exclusions have not been tampered with or added without administrative authorization.
  • Practicing stringent operational security, including exercising extreme caution when receiving unsolicited files, documents, or software installation requests via messaging apps, regardless of whether the sender appears to be a trusted acquaintance.

Implications for Global Cybersecurity and Civil Society

The emergence of CHOSEN BRICK highlights a grim reality in modern digital conflict: advanced offensive cyber capabilities are increasingly being democratized and directed toward asymmetrical warfare against vulnerable civilians rather than solely against critical infrastructure or military targets.

As nation-state actors continue to refine their tooling, the line between traditional espionage and targeted harassment continues to blur. For civil society organizations, media outlets, and advocacy groups, protecting high-risk personnel requires a paradigm shift. Standard enterprise IT security is no longer sufficient; human-centric digital hygiene, rigorous verification of communication channels, and advanced end-user monitoring are now mandatory safeguards.

Ultimately, the joint advisory by international intelligence agencies serves as both a technical warning and a geopolitical statement. By unmasking tools like CHOSEN BRICK and exposing the operational infrastructure of Iranian threat actors, Western governments aim to disrupt ongoing surveillance campaigns, raise the operational costs for state-sponsored hackers, and provide actionable intelligence to the individuals most at risk of falling victim to digital authoritarianism.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.