Iranian Hackers Deploy 'CHOSEN BRICK' Malware to Target Dissidents Globally
Government agencies from the U.S., U.K., and the Netherlands have issued a joint advisory warning about a sophisticated Iranian state-linked hacking campaign. This operation utilizes a new Windows malware strain dubbed **CHOSEN BRICK** to conduct espionage against dissidents, activists, and journalists worldwide, employing advanced social engineering tactics and data exfiltration techniques.
A recent joint advisory by cybersecurity agencies in the U.S., U.K., and the Netherlands, alongside the **FBI**, reveals an ongoing espionage campaign by Iranian state-linked threat actors. The campaign primarily targets individuals perceived as threats to the Iranian regime, focusing on those in the U.S., U.K., and the Netherlands.
### The CHOSEN BRICK Malware
At the heart of this campaign is **CHOSEN BRICK**, a Windows malware strain equipped with extensive data theft and espionage capabilities. This sophisticated tool is designed to collect sensitive information, including email, **Telegram**, and **WhatsApp** communications, capture screenshots, and record audio.
### Social Engineering: The Initial Vector
The attack chain typically begins with highly convincing social engineering messages. Threat actors impersonate trusted contacts or technical support agents, reaching out to targets via **WhatsApp** or **Telegram**. Victims are then tricked into opening malicious files disguised as legitimate applications, such as **Pictory**, **RunwayML**, **Norton Antivirus**, **Telegram**, **Adobe Flash Player**, and **KeePass**.
Intriguingly, the attackers often suggest launching these files on personal devices, aiming to bypass corporate security measures. In some instances, the lures have even incorporated medical themes.

Upon execution, these seemingly legitimate applications display a convincing interface while silently installing **CHOSEN BRICK** in the background. Persistence is secured through **Windows Registry Run keys**, and the malware attempts to evade detection by adding exclusions to **Microsoft Defender**.
### Command and Control via Telegram
**CHOSEN BRICK** establishes its command-and-control (C2) channel through a unique **Telegram** bot, specifically tailored to each victim's ID. This method allows the attackers to issue commands and receive exfiltrated data stealthily.
Once active, **CHOSEN BRICK** can perform a wide array of malicious actions:
* Collect system information
* Enumerate running processes
* Capture screenshots
* Record audio via the microphone
* Steal email content
* Steal **Telegram** or **WhatsApp** browser data
* Download additional payloads to `C:\Windows\SysWOW64`
* Delete files
* Wipe the entire host system
### Data Exfiltration and Operational Security
Stolen data is exfiltrated through **Telegram** or cloud services like **VultrObjects** and **StorjShare**. Newer variants of **CHOSEN BRICK** employ **SOCKS5 proxies** to route traffic, further obscuring their activities and enhancing operational security.
### Real-World Consequences
The advisory highlights a disturbing trend: exfiltrated data sometimes surfaces on pro-Iranian leak sites. This tactic serves as a form of harassment and significantly increases the physical risk for dissidents living abroad. The agencies explicitly state that "Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime." They also note that Iranian intelligence services have previously "plotted to kidnap or conduct lethal operations against individuals internationally."
### Recommendations for Defenders
To mitigate the risk of **CHOSEN BRICK** infections, potential victims and organizations are advised to:
* Inspect **Registry Run entries** for any suspicious additions.
* Search logs for the **Indicators of Compromise (IoCs)** detailed in the joint advisory.
* Investigate unexpected connections to **Telegram's API**, **Backblaze B2**, **VultrObjects**, **StorjShare**, **IPRoyal**, and **LightningProxies** as potentially malicious activity.