ZCyberNews
中文
MalwareHigh4 min readCHOSEN BRICK

CHOSEN BRICK: Iranian Malware Hits Dissidents via Telegram

NCSC, FBI and AIVD warn that Iranian state actors use CHOSEN BRICK malware, delivered via WhatsApp and Telegram social engineering, to spy on dissidents and journalists.

TopicMalware
Illustration of a smartphone with messaging app icons and a malware warning symbol

Executive Summary

Iranian state cyber actors are using a malware family tracked as CHOSEN BRICK to target dissidents, activists, and journalists in the UK, US, and Netherlands, according to a joint advisory from the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands' General Intelligence and Security Service (AIVD). The malware, active since at least 2025, enables collection of contacts, emails, and social media messages, and can activate the microphone and capture screen content. The advisory provides technical analysis of the attack chain and mitigation advice.

Technical Analysis

CHOSEN BRICK is a persistent Windows malware family that Iranian state actors use to conduct surveillance on individuals perceived as threats to the regime. The actors tailor their approach to each target, but the core pattern involves initial contact via social messaging platforms such as WhatsApp and Telegram, where they pose as trusted entities. After building rapport, they convince targets to download and open files disguised as legitimate applications—examples include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass—or as MRI scan results. The malicious files display a legitimate-looking screen while downloading and executing the CHOSEN BRICK core component in the background.

Once installed, CHOSEN BRICK achieves persistence by adding a registry key, typically under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, so it runs at user login. It also adds exclusions to Microsoft Defender antivirus to evade detection. For command and control, the malware connects to Telegram, with each victim device using a unique Telegram Bot ID as an operational security measure to prevent cross-contamination between victims. The malware can download additional payloads and set up persistence for them using the same registry key.

The malware's capabilities include enumerating running processes and system information, capturing screen content, enabling the microphone to record audio, stealing Telegram and WhatsApp data from web browsers, downloading additional files, deleting files, stealing email content, and wiping the computer system. While no automated lateral movement has been observed, the ability to download additional malware makes it technically possible.

Tactics, Techniques & Procedures

The attack chain follows a consistent sequence. First, the actors gather victim identity information (T1589) through extensive research. They then initiate contact via social messaging platforms, often impersonating a known contact or technical support (T1566.003). After building rapport, they deliver a malicious file that the victim is convinced to open (T1204.002). The file executes the CHOSEN BRICK malware, which establishes persistence via registry Run keys (T1547.001) and disables or modifies tools by adding Defender exclusions (T1685). Command and control is conducted through Telegram's web service (T1102.002). Post-compromise, the malware performs process discovery (T1057), system information discovery (T1082), screen capture (T1113), audio capture (T1123), data from local system (T1005), email collection (T1114.001), and data destruction (T1485).

Threat Actor Context

The advisory attributes the activity to Iranian state cyber actors. Iran almost certainly uses cyber activity to support repression of individuals seen as threats to the regime. In some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally. The personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing risks to their personal safety. The joint advisory is issued by the NCSC, FBI, and AIVD, indicating a coordinated international response.

Mitigations & Recommendations

Individuals and organizations should be aware of the social engineering tactics used to deliver CHOSEN BRICK. Avoid opening files or clicking links from unknown contacts on messaging platforms, even if they appear to be from trusted entities. Verify the identity of anyone requesting you to download or open files. Use endpoint detection and response (EDR) tools to monitor for registry modifications, especially Run key persistence, and for anomalous Telegram traffic. Organizations should consider blocking or monitoring Telegram if not required for business, and ensure that Microsoft Defender exclusions are audited regularly. For high-risk individuals such as journalists and activists, consider using hardened devices and secure communication channels. The NCSC advisory provides further technical details and mitigation advice.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Tags:#chosen-brick#iran#state-sponsored#malware#social-engineering#telegram

Related Articles