Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide.
The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio.
The threat actor primarily targeted individuals in the U.S., U.K., and the Netherlands, whose cybersecurity agencies published a joint advisory with the FBI.
A typical attack begins with social engineering messages impersonating trusted contacts or technical support agents, sent to targets via WhatsApp or Telegram.
The threat actor tricks victims into opening malicious files disguised as legitimate applications (e.g., Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass), often suggesting they launch them on personal devices to bypass corporate security blocks.
Depending on the pretext used, the hackers sometimes used even medical-related lures, the agencies found.
MRI scan document used as lure
Source: NCSC
The apps display a convincing interface that matches the lure, while silently installing CHOSEN BRICK in the background and securing persistence through Windows Registry Run keys.
The malware adds Microsoft Defender exclusions to evade detection and connects to a unique Telegram bot that matches the victim’s ID and provides command-and-control (C2).
... continue reading