Cybersecurity

Warning About CHOSEN BRICK Malware Targeting Dissidents and Journalists Worldwide

Government agencies warn of an espionage campaign linked to Iranian entities that uses Windows malware called CHOSEN BRICK to steal email and Telegram and WhatsApp data, capture images, and record audio. The campaign relies on impersonation messages and malicious files disguised as well-known applications, while using Telegram and cloud storage services for communication and data exfiltration.

2026-09-16
4 min read
3 views
فريق تحرير certi.news
Warning About CHOSEN BRICK Malware Targeting Dissidents and Journalists Worldwide

Government agencies have warned that Iran-linked entities are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists around the world. The targets identified by the agencies were concentrated among individuals in the United States, the United Kingdom, and the Netherlands, prompting the cybersecurity authorities of the three countries, in cooperation with the U.S. Federal Bureau of Investigation, to issue a joint warning.

Social Engineering Disguised as Familiar Applications

The attacks typically begin with messages sent via WhatsApp or Telegram that impersonate a trusted contact or technical support employee. The attackers attempt to persuade the victim to open malicious files that appear to be legitimate applications, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. In some cases, the campaign used pretexts related to medical services.

The messages sometimes request that the files be run on a personal device, in an attempt to bypass the security restrictions imposed on organizational devices. After the file is opened, the process displays an interface that appears consistent with the application or service used in the lure, while CHOSEN BRICK is installed in the background. The malware uses Run keys in the Windows Registry to ensure that it continues running after the device is restarted.

Extensive Data-Collection and Device-Control Capabilities

CHOSEN BRICK can collect system information and enumerate running processes, in addition to capturing screenshots and recording audio through the microphone. It can also steal email content and Telegram and WhatsApp data stored in the browser, and download additional payloads to the C:\Windows\SysWOW64 path.

Its functions are not limited to espionage; commands allow it to delete files and even wipe the entire host system. The malware connects to a unique Telegram bot associated with the victim's identifier, which serves as a command-and-control channel. More recent samples have also shown the use of SOCKS5 proxies to conceal the communications path.

Data-Exfiltration Channels and Examination Indicators

Stolen data is sent through Telegram or cloud-storage services, including VultrObjects and StorjShare. The agencies noted the need to investigate unexpected connections to the Telegram API, Backblaze B2, VultrObjects, and StorjShare, in addition to IPRoyal and LightningProxies.

The guidance recommends examining Registry Run entries for unfamiliar items and reviewing logs using the indicators of compromise included in the joint warning.

Why Does This News Matter?

The danger of the campaign lies not only in data theft, but also in the fact that the stolen information may sometimes end up on Iran-aligned leak sites, turning the intrusion into a harassment tool that could increase the physical risks faced by dissidents outside Iran. The agencies say the cyber activity is likely being used to support the suppression of individuals whom the Iranian authorities consider threats, noting that Iranian intelligence services have in some cases planned to kidnap or carry out lethal operations against people outside the country.

In practical terms, the warning shows that relying on an application's name or appearance is not sufficient to determine whether a file is safe, particularly when the invitation to run it comes through a personal messaging channel. As for the infrastructure details and indicators of compromise, they remain tied to the information contained in the government guidance, making it necessary for teams investigating an actual incident to review the original version.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news