
Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio.
The malware has been used internationally since at least 2025 and relies heavily on social engineering, while also using Telegram infrastructure for command-and-control.
The findings were published in a joint advisory from the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands’ General Intelligence and Security Service (AIVD). According to their assessment, CHOSEN BRICK has targeted people in several countries, including the UK, US, and Netherlands.
Attacks begin with extensive research into prospective victims, followed by social engineering over messaging services such as WhatsApp and Telegram. Attackers may impersonate someone the target already knows or pose as technical support to build trust before sending a malicious file.
Observed lures have masqueraded as legitimate applications including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. Other attacks delivered files presented as MRI scan results. The malicious files display convincing content matching the pretext while silently installing CHOSEN BRICK in the background. All infections documented in the advisory targeted Windows systems.

FBI
Once installed, CHOSEN BRICK typically gains persistence through the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key and can add Microsoft Defender exclusions to reduce the chance of detection. It then communicates with Telegram for command-and-control, with operators assigning a separate Telegram bot ID to each victim.
The malware can enumerate running processes and system information, take screenshots, activate the microphone, steal email, and copy Telegram and WhatsApp browser data. Operators can also download additional malware, delete files, and, in at least one analyzed sample, wipe the compromised computer.
Stolen information can be exfiltrated through Telegram or cloud-storage services including VultrObjects and StorjShare. More recent variants can route traffic through HTTPS or SOCKS5 proxies to help conceal their Telegram communications. The advisory also notes that personal information obtained from some previous victims later appeared on pro-Iranian leak sites.
People at higher risk should avoid installing software received through messages or unexpected links and instead download applications directly from official sites or app stores. The agencies also recommend keeping Windows and applications updated, maintaining active antivirus protection, and never ignoring or bypassing SmartScreen warnings.






Leave a Reply