Tracking Elirks Variants in Japan: Similarities to Previous Attacks
Unit 42 links new Elirks backdoor variants attacking Japanese organizations to 2012 Taiwan attacks, delivered via spear-phishing PDFs exploiting Adobe Flash CVE-2011-0611.
Unit 42 analyzed new Elirks backdoor variants found in an attack on a Japanese business, noting strong similarities to 2012 attacks on Taiwanese ministries. The backdoor retrieves its C2 address from attacker-created accounts on Japanese blog and SNS services. Recent deliveries used an airline e-ticket lure named "E-TKT" with a PDF exploiting Adobe Flash CVE-2011-0611. Shared infrastructure and tactics with the Scarlet Mimic campaign suggest possible ongoing cyber espionage across East Asia.
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
China-linked Jewelbug runs government espionage and crypto fraud from a single XG-Web browser-based control framework.
Broadcom's Symantec and Carbon Black detail Jewelbug, a China-based hackers-for-hire group conducting espionage against governments and militaries in the Middle East, Southeast Asia, and South Asia, plus crypto fraud against Chinese-speaking victims. Operations center on XG-Web, a browser-centric remote-access and infostealing framework, with implants spanning browsers, Windows, Linux, and network devices. The group overlaps with CL-STA-0049, Ink Dragon, Earth Alux, and REF7707, and compromised a Middle Eastern government's webmail across 15 tenants.
“Tick” Group Continues Attacks
Unit 42 tracks the Tick espionage group attacking Korean and Japanese defense and high-tech targets with Daserf, Minzen, 9002, Invader, and custom Gh0st RAT variants.
The Tick group has conducted long-running espionage attacks against organizations in the Republic of Korea and Japan, focusing on defense and high-tech companies holding intellectual property, and repeatedly attacked one high-profile Japanese target for three years. Unit 42 links the Daserf backdoor, the 9002 RAT, and the Invader backdoor through shared C2 infrastructure used between July 2012 and April 2013. Minzen samples install a "NamelessHdoor" backdoor derived from publicly available code over a decade old, modified with ReflectiveDLLLoader DLL injection, and the group also uses custom Gh0st RAT variants. Tick has shifted from privacy-protected domain registration to compromised websites for C2 infrastructure.
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, BlueKeep exploitation, and covert tunneling for espionage.
Kaspersky's Global Emergency Response Team attributes new intrusions against Russian companies to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asian organizations. The group uses valid VPN credentials, deploys the .NET-based GhostContainer backdoor on Microsoft Exchange servers, and tunnels RDP via Microsoft Dev Tunnels and rdp2tcp. In one incident operators exploited BlueKeep (CVE-2019-0708) to create an administrator account, and they performed DCSync replication against Active Directory to harvest domain password hashes. GhostContainer reuses code from Neo-reGeorg, ExchangeCmdPy.py (CVE-2020-0688), and ysoserial, and tampers with AMSI and Windows event logging to evade detection.
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, and Microsoft Dev Tunnels abuse.
Kaspersky's Global Emergency Response Team attributes new intrusions against Russian organizations to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asia. Initial access uses valid VPN credentials, followed by the .NET GhostContainer backdoor on Microsoft Exchange servers, which abuses ASP.NET view state injection, disables AMSI and event logging, and proxies traffic. Operators moved laterally via RDP, abused Microsoft Dev Tunnels with rdp2tcp, used Impacket atexec and netsh portproxy, and in one case exploited BlueKeep (CVE-2019-0708) to create admin accounts and attempt DCSync.
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Iranian state-linked hackers use CHOSEN BRICK Windows malware, spread via Telegram and WhatsApp social engineering, to spy on dissidents and journalists worldwide.
US, UK, and Dutch cyber agencies with the FBI issued a joint advisory on Iranian state-linked hackers deploying a Windows malware strain called CHOSEN BRICK against dissidents, activists, and journalists, primarily in the US, UK, and Netherlands. Attacks begin with messages on WhatsApp or Telegram impersonating trusted contacts or technical support, tricking victims into running malicious files disguised as apps such as Pictory, RunwayML, Norton Antivirus, Telegram, and KeePass. The malware persists via Registry Run keys, adds Microsoft Defender exclusions, and uses a per-victim Telegram bot for command-and-control while stealing email, Telegram and WhatsApp data, screenshots, and audio. Stolen data is exfiltrated via Telegram or cloud services like VultrObjects and StorjShare, and sometimes appears on pro-Iranian leak sites, increasing physical risk for dissidents abroad.
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
UK NCSC, FBI and Dutch AIVD warn Iranian state hackers deploy CHOSEN BRICK spyware via WhatsApp and Telegram lures against dissidents and journalists since 2025.
The UK's NCSC, the FBI and the Netherlands' AIVD jointly warned that Iranian state cyber actors have deployed CHOSEN BRICK against dissidents, activists and journalists in the UK, US and Netherlands since at least 2025. Victims are contacted on WhatsApp or Telegram by impostors posing as known contacts or platform support, then tricked into running files disguised as software such as fake Norton Antivirus, KeePass, Telegram or MRI scan results. The Windows malware adds Microsoft Defender exclusions, persists via HKCU Run keys, uses per-device Telegram bots for C2, and can capture screens, activate microphones, steal email and messaging data, and download further payloads. Some stolen data has later appeared on pro-Iranian leak sites, and the agencies note Iranian intelligence has plotted kidnappings or lethal operations against targets abroad.
NCSC and Allies Warn of Iranian Spyware Campaign
NCSC, FBI and AIVD warn Iranian-backed actors deliver Chosen Brick spyware to regime critics via social engineering; stolen data has surfaced on pro-Iranian leak sites.
NCSC, the FBI and the Netherlands' AIVD published a joint advisory warning that a Tehran-backed campaign, active since at least 2025, targets dissidents, activists and journalists with Chosen Brick spyware. The malware persists via Windows registry keys, adds Microsoft Defender exclusions, uses Telegram for C2, and captures screens, audio, emails and Telegram or WhatsApp messages. Stolen data has surfaced on pro-Iranian leak sites in some cases, raising risks to victims' personal safety.
Iranian spies hit Windows machines with Chosen Brick data-stealing malware
FBI, UK NCSC, and Dutch AIVD warn Iranian intelligence uses Chosen Brick spyware against dissidents, stealing contacts, emails, and messaging data.
A joint advisory from the FBI, UK NCSC, and Dutch AIVD says Iranian state cyber actors have used the Chosen Brick Windows malware since at least 2025 to surveil dissidents, activists, and journalists. Attacks begin with heavily researched WhatsApp and Telegram messages impersonating trusted contacts, tricking victims into opening fake installers resembling Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware persists via the HKCU Run registry key, adds Microsoft Defender exclusions, uses victim-specific Telegram bots for C2, captures screen and audio, steals emails and Telegram/WhatsApp data, and can wipe systems.
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.
The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.
Iranian cyber targeting of dissidents, activists and journalists
UK NCSC, FBI, and Dutch AIVD expose CHOSEN BRICK spyware used by Iranian state actors against dissidents, activists, and journalists worldwide.
A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK, a Windows spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists, and journalists in the UK, US, and Netherlands. Actors build rapport on WhatsApp and Telegram impersonating known contacts or platform support, then deliver disguised payloads resembling apps such as Telegram, Norton, RunwayML, or fake MRI results. The malware persists via HKCU Run registry keys, adds Microsoft Defender exclusions, and uses a unique Telegram bot C2 per victim. Capabilities include screen capture, microphone recording, process enumeration, email and messaging data theft, file deletion, and system wiping; victim data has appeared on pro-Iranian leak sites.