US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch agencies warn Iranian state actors deploy Windows surveillance malware 'Chosen Brick' against dissidents, activists, and journalists worldwide.
Joint advisories from US, UK, and Dutch agencies describe Chosen Brick, a Windows surveillance malware active since at least 2025 and used by Iranian state cyber actors to track regime opponents. The malware harvests contacts, emails, and social media messages, persists via registry Run keys, evades Microsoft Defender, and uses per-victim Telegram bot IDs for command-and-control and exfiltration. Operators build rapport on WhatsApp and Telegram posing as acquaintances or support staff, disguising payloads as utility software or fake medical documents. Capabilities include screenshot capture, audio recording, credential theft, secondary payload delivery, and data wiping.
- Targets Windows, harvesting contacts, emails, chat data, and life-pattern information of regime critics
- Persistence via registry Run keys; adds Microsoft Defender exclusions to evade local security tools
- Each victim gets a unique Telegram bot ID for C2; exfiltration via Telegram and cloud storage
- Victims approached on WhatsApp or Telegram; payloads disguised as utilities or fake MRI results
- Can capture screenshots, record audio, steal emails, deploy secondary payloads, and wipe data
Full article394 words · extracted from securityweek.com · click to collapse
Cybersecurity and intelligence agencies in the US, UK, and Netherlands have issued a joint advisory warning of a Windows malware family dubbed Chosen Brick, deployed by Iranian state cyber actors to target dissidents, activists, and journalists worldwide.
Active since at least 2025, Chosen Brick is leveraged by Iranian operators to harvest contacts, emails, social media messages, and other types of data that can be used to track an individual’s location and life patterns.
The agencies noted that the activity directly supports state-sponsored repression against individuals perceived as threats to the regime, with stolen personal information occasionally posted to pro-Iranian leak sites to harass targets.
The attack chain typically begins on messaging platforms such as WhatsApp and Telegram. Operators research their targets to build rapport, often posing as acquaintances or platform technical support representatives before delivering weaponized files.
Attackers frequently initiate contact through a target’s corporate device. However, if security controls block delivery, the attackers try to shift the interaction to the individual’s personal device to bypass enterprise protections.
To trick victims, threat actors disguise malicious installers as legitimate utility software or as fake medical documentation, such as MRI scan results. When opened, the file displays a decoy screen while stealthily executing the malware in the background.
Advertisement. Scroll to continue reading.
All observed infections have targeted Windows. Upon execution, Chosen Brick establishes persistence across reboots using registry Run keys and attempts to evade local security tools by adding exclusions in Microsoft Defender.
For command-and-control (C&C) operations, the malware assigns each infected endpoint a unique Telegram bot ID to maintain operational security and prevent cross-victim contamination. Exfiltration occurs through the Telegram infrastructure and cloud storage services.
The FBI has separately published a document describing how Iranian state-sponsored hackers have used Telegram as C&C infrastructure in malware attacks targeting the regime’s opponents.
Chosen Brick contains extensive surveillance and destructive capabilities. Operators can capture screenshots, record host audio via the microphone, extract browser-stored chat data, steal emails, deploy secondary malware payloads, and execute commands to wipe data.
While the malware lacks automated lateral movement capabilities, its ability to download secondary payloads lets operators expand access manually.
Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/