Skip to content
Tech News
← Back to articles

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

This report highlights an active, government-confirmed Iranian state-sponsored spyware campaign targeting journalists, activists, and dissidents in the US, UK, and Netherlands, underscoring the ongoing risk of state actors weaponizing everyday messaging apps for surveillance. It matters because it shows how social engineering combined with disguised legitimate-looking software can bypass both personal vigilance and corporate security controls, putting at-risk individuals' communications and safety in jeopardy.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — Given how this campaign relies on social engineering and tricking targets into installing malicious apps, adding hardware-backed multi-factor authentication is a smart defense layer. A YubiKey lets journalists and activists secure their email, Telegram, and other accounts against credential theft even if a device gets compromised. It's a simple, tangible step toward better personal security hygiene.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide.

The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio.

The threat actor primarily targeted individuals in the U.S., U.K., and the Netherlands, whose cybersecurity agencies published a joint advisory with the FBI.

A typical attack begins with social engineering messages impersonating trusted contacts or technical support agents, sent to targets via WhatsApp or Telegram.

The threat actor tricks victims into opening malicious files disguised as legitimate applications (e.g., Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass), often suggesting they launch them on personal devices to bypass corporate security blocks.

Depending on the pretext used, the hackers sometimes used even medical-related lures, the agencies found.

MRI scan document used as lure

Source: NCSC

The apps display a convincing interface that matches the lure, while silently installing CHOSEN BRICK in the background and securing persistence through Windows Registry Run keys.

The malware adds Microsoft Defender exclusions to evade detection and connects to a unique Telegram bot that matches the victim’s ID and provides command-and-control (C2).

... continue reading