Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
IncidentMalwareWorld

Iranian Hackers Deploy CHOSEN BRICK Malware

By ogwatermelon
September 17, 2026 3 Min Read
0

September 16, 2026

Government agencies in the United States, United Kingdom, and the Netherlands have issued a joint warning about an Iranian state-linked espionage campaign that deploys a Windows malware strain named CHOSEN BRICK. The malware targets dissidents, activists, and journalists with advanced data theft and surveillance capabilities. In addition, the agencies disclosed that Iranian intelligence services have plotted kidnappings and lethal operations against perceived enemies abroad. Consequently, the threat extends beyond data to physical safety.

What Happened: Iranian Hackers Deploy CHOSEN BRICK Malware Against Activists and Journalists

The FBI, NCSC-UK, and Dutch security agencies published a joint advisory on September 16, 2026, detailing how Iranian state-backed hackers use CHOSEN BRICK to spy on high-risk individuals worldwide. The malware primarily targets people in the U.S., U.K., and the Netherlands who are seen as threats to the Iranian regime.

Moreover, the agencies warned that stolen data sometimes surfaces on pro-Iranian leak sites. Therefore, the campaign serves both espionage and harassment purposes, which increases the physical danger for victims.

Technical Details of the CHOSEN BRICK Malware

CHOSEN BRICK is a Windows-based malware family that relies on social engineering for initial access. The threat actor sends convincing messages through WhatsApp or Telegram that impersonate trusted contacts or technical support agents. Furthermore, the messages urge victims to open malicious files disguised as legitimate applications such as Pictory, RunwayML, Norton Antivirus, KeePass, or even MRI scan documents.

Once executed, the fake application displays a convincing interface while silently installing CHOSEN BRICK in the background. The malware secures persistence through Windows Registry Run keys and adds Microsoft Defender exclusions to evade detection. After installation, it connects to a unique Telegram bot that matches the victim’s ID and provides command-and-control (C2) communication.

CHOSEN BRICK Capabilities

  • Collect system information
  • Enumerate running processes
  • Capture screenshots
  • Record audio through the microphone
  • Steal email content
  • Steal Telegram or WhatsApp browser data
  • Download additional payloads to “C:\Windows\SysWOW64”
  • Delete files
  • Wipe the entire host system

Newer CHOSEN BRICK variants route C2 traffic through SOCKS5 proxies and exfiltrate stolen data via Telegram, VultrObjects, or StorjShare cloud services. In addition, the attackers have shifted to cloud-based dead drops to make detection harder.

Business and Operational Impact

The CHOSEN BRICK campaign poses serious risks for individuals and organizations that support at-risk communities. The impact includes:

  • Privacy loss: Compromised communications, documents, and personal data
  • Physical danger: Leaked data published on pro-regime sites can enable harassment or worse
  • Reputational harm: Organizations hosting activists may face public exposure of supporter networks
  • Operational disruption: Host wiping can destroy evidence and halt time-sensitive work

Therefore, NGOs, newsrooms, and human rights groups should treat this as a high-priority threat.

Mitigation and Recommendations

The agencies recommend immediate defensive actions to detect and block CHOSEN BRICK activity.

Immediate Actions for Defenders

  1. Inspect Windows Registry Run entries for suspicious values
  2. Review logs for indicators of compromise shared in the joint advisory
  3. Investigate unexpected connections to Telegram’s API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies
  4. Search for unusual .exe or .dll files in “C:\Windows\SysWOW64”
  5. Audit Microsoft Defender exclusion lists for unauthorized changes

User Awareness and Training

At-risk individuals should avoid installing software from unsolicited messages, even if the sender appears trusted. Moreover, they should verify application downloads through official vendor websites and use multi-factor authentication on sensitive accounts.

Bottom line: Iranian state-linked hackers are actively using CHOSEN BRICK to surveil and harass dissidents, activists, and journalists. Organizations that serve these communities must harden endpoints, review network logs, and train users to resist social engineering lures.

Incident Summary

Campaign / Malware: CHOSEN BRICK (Iranian state-linked espionage)
Affected Targets: Dissidents, activists, and journalists in the U.S., U.K., and the Netherlands
Disclosure Date: September 16, 2026
Patch Status: No single patch available; defense relies on detection and user awareness
Severity: High (state-sponsored espionage with physical safety implications)

References

  1. National Cyber Security Centre (UK), FBI, and Dutch Security Agencies, “Iranian Cyber Targeting of Dissidents, Activists, and Journalists,” Joint Advisory, September 16, 2026, https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists, accessed September 16, 2026.
  2. Bill Toulas, “Iranian hackers use CHOSEN BRICK Windows malware to spy on targets,” BleepingComputer, September 16, 2026, https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/, accessed September 16, 2026.

Tags:

ExploitIncidentWorld
Author

ogwatermelon

Follow Me
Other Articles
Previous

Ransomware Gangs Exploit Critical VMware vCenter RCE CVE

Next

Critical Unbound DNSSEC Validator RCE via Malicious DNS Zone

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.