Iranian Hackers Use CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain called CHOSEN BRICK to target dissidents, activists, and journalists worldwide.
The malware can steal data and spy on victims by collecting email, Telegram, and WhatsApp communications, capturing screenshots, and recording audio through a device’s microphone.
The attackers primarily targeted individuals in the United States, United Kingdom, and the Netherlands. The UK National Cyber Security Centre (NCSC), alongside the FBI, published a joint recommendation containing details about the campaign.
How the CHOSEN BRICK malware attacks victims
A typical attack begins with a social engineering message sent through WhatsApp or Telegram. The threat actor pretends to be a trusted contact or a technical support agent before persuading the target to open a malicious file.
The files are disguised as legitimate applications, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. In many cases, attackers encourage victims to launch the files on personal devices to bypass security controls that may block them on corporate systems.
Authorities also found that the attackers used medical-related decoys, including a malicious file disguised as an MRI scan document.

Source: NCSC
The malicious application displays a convincing interface that matches the lure while silently installing CHOSEN BRICK in the background. The malware establishes persistence by adding a Run key to the Windows registry, allowing it to launch automatically when the victim signs in.
CHOSEN BRICK also adds exclusions to Microsoft Defender to reduce the chance of detection. It connects to a Telegram bot associated with the victim’s identity, which the attackers use for command and control (C2).
What CHOSEN BRICK can do
Once installed, CHOSEN BRICK can perform a range of surveillance and destructive actions, including:
- Collecting system information
- Enumerating running processes
- Capturing screenshots
- Recording audio through the microphone
- Stealing email content
- Stealing Telegram and WhatsApp browser data
- Downloading additional payloads to
C:\Windows\SysWOW64 - Deleting files
- Wiping the entire host system
How the malware exfiltrates stolen data
Stolen information is exfiltrated through cloud services such as Telegram, VultrObjects, and StorjShare. New CHOSEN BRICK variants can conceal their activity by routing traffic through SOCKS5 proxies.
The advisory warns that stolen data may be published on pro-Iranian leak sites. This can be used to harass dissidents and increase the physical risks faced by targets living abroad.
“Iran almost certainly uses cyber operations to support the repression of individuals deemed a threat to the regime, including dissidents, activists, and journalists,” the agency said.
“In some cases, Iranian intelligence services have planned kidnapping and lethal operations against international individuals they perceive as enemies of the regime.”
How to detect CHOSEN BRICK activity
Potential victims and organizations should inspect Windows registry execution entries for suspicious Run keys and review security logs for the indicators of compromise (IoCs) listed in the advisory.
Unexpected connections to the following services should also be investigated:
- Telegram’s API
- Backblaze B2
- VultrObjects
- StorjShare
- IPRoyal
- LightningProxies
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



