US, UK, and Dutch Agencies Uncover Iranian ‘Chosen Brick’ Surveillance Malware

www.news4hackers.com-us-uk-and-dutch-agencies-uncover-iranian-chosen-brick-surveillance-malware-us-uk-and-dutch-agencies-uncover-iranian-chosen-brick-surveillance-malware

US, UK, and Dutch cybersecurity authorities have released a joint warning about a Windows-based malware family known as Chosen Brick, linked to Iranian state-sponsored cyber operations.

Overview of Chosen Brick Malware

Chosen Brick, first observed in 2025, enables threat actors to collect sensitive data such as contact lists, email exchanges, social media interactions, and other digital footprints that could reveal a target’s location and behavioral patterns. The malware has been used to target individuals including dissidents, activists, and journalists globally.

Targeted Individuals

The agencies stated that the campaign aligns with broader efforts by Iranian operatives to suppress opposition and monitor critical infrastructure.

Attack Process and Initial Infection Methods

The attack process typically begins through messaging platforms like Telegram. Threat actors conduct reconnaissance to establish trust, often impersonating colleagues or technical support personnel. They initially attempt to deliver malicious payloads via corporate devices but switch to personal devices if enterprise defenses block the initial approach.

Malicious Payload Delivery

The malware is disguised as legitimate software or fabricated medical documents, such as MRI reports. Once executed, the file displays a deceptive interface while silently deploying the malicious code in the background.

Technical Capabilities and Evasion Techniques

All confirmed infections have occurred on Windows systems. Upon activation, Chosen Brick ensures persistence by modifying registry Run keys and evades detection by configuring exclusions in Microsoft Defender. For command-and-control (C&C) communications, the malware assigns each compromised device a unique Telegram bot identifier, enhancing operational security.

Advanced Surveillance Features

The FBI has separately disclosed details about the malware’s capabilities, highlighting its extensive surveillance and destructive features. Attackers can capture screenshots, record audio through microphones, extract chat data from web browsers, steal email credentials, deploy additional malware, and execute commands to erase data.

Security Implications and Recommendations

Although the malware does not support automated lateral movement within networks, its ability to exfiltrate sensitive information and disrupt operations remains a significant threat. The joint advisory underscores the persistent use of sophisticated tools by state-sponsored groups to conduct targeted cyber operations.

Urgent Security Measures

Security professionals are urged to implement robust endpoint protections, monitor for unusual network activity, and educate users about social engineering tactics. The release of this information aims to strengthen global defenses against similar threats.

According to the FBI, Chosen Brick’s capabilities include capturing screenshots, recording audio, extracting chat data, stealing email credentials, deploying additional malware, and erasing data.



About Author

en_USEnglish