www.securityweek.com 16 Sept 2026, 12:00 UTC

Iranian Hackers Use Chosen Brick Malware to Target Dissidents Worldwide

Iranian Hackers Use Chosen Brick Malware to Target Dissidents Worldwide

US , UK and Dutch cybersecurity and intelligence agencies have issued a joint advisory about Chosen Brick, a Windows malware family used by Iranian state actors against dissidents, activists and journalists worldwide. The activity has been observed since at least 2025 and is intended to collect contacts, emails, social-media messages and other information that could reveal victims’ locations and routines. The agencies said the stolen data supports state-sponsored repression and has sometimes been published on pro-Iranian leak sites to harass targets.

Attacks generally start on WhatsApp or Telegram, where operators research victims, build trust and pose as acquaintances or technical-support staff. They send weaponised files disguised as utility software or medical documents such as MRI results. The file shows a decoy screen while installing the malware, often first targeting a corporate device before moving to a personal one if enterprise controls block it.

Chosen Brick persists through registry Run keys, adds Microsoft Defender exclusions and uses Telegram bots and cloud storage for command-and-control and data theft. Its capabilities include screenshots, microphone recording, browser-stored chat theft, email collection, secondary-payload delivery and commands to wipe data. It has no automated lateral movement, although operators can expand access manually using downloaded payloads. The advisory’s practical implication is to scrutinise unsolicited files and suspicious contacts on both corporate and personal Windows devices.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline