www.ncsc.gov.uk 15 Sept 2026, 12:00 UTC

Iranian Hackers Target Dissidents Worldwide With CHOSEN BRICK Malware

Iranian Hackers Target Dissidents Worldwide With CHOSEN BRICK Malware

THE UK National Cyber Security Centre (NCSC), US Federal Bureau of Investigation and Dutch AIVD have warned that Iranian state cyber actors have used the CHOSEN BRICK malware to target dissidents, activists and journalists worldwide, including in the UK, US and Netherlands, from at least 2025. Some victims’ personal details have subsequently appeared on pro-Iranian leak sites, potentially increasing risks to their safety.

The agencies say the operations support Iran’s repression of people viewed as threats to the regime, although the advisory does not say that every target has been successfully compromised.

Attackers build rapport through WhatsApp, Telegram and other messaging platforms, often posing as trusted contacts or technical support after researching their targets. They then persuade victims to open files disguised as legitimate software, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player or KeePass, or as MRI results. The Windows-only malware can persist through the registry Run key, add Microsoft Defender exclusions and use Telegram bots for command and control.

It can capture screens and microphone audio, steal email and browser-based Telegram or WhatsApp data, download further malware, delete files and potentially wipe systems. Automated lateral movement has not been observed.

Organisations concerned about compromise should involve their IT providers, search logs for the advisory’s indicators and detection signatures, and help staff check personal Windows devices. Investigators should examine `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and unexpected connections to services including `api.telegram.org`, `vultrobjects.com` and `storjshare.io`; example filenames are not exclusive indicators.

The agencies recommend avoiding software delivered through messages, using official download sources, keeping systems and antivirus updated, and not bypassing SmartScreen warnings.

View full article

Article by CyberSIXT