Iran's Chosen Brick Malware Targets Dissidents
A joint advisory from the UK, FBI, and Netherlands warns that Iranian hackers use social engineering and messaging apps to spy on and wipe victims' systems.
Iranian state-linked hackers are using a sophisticated malware strain called Chosen Brick to spy on and disrupt individuals they label enemies of the state, according to a new joint security advisory. The warning, issued by the UK National Cyber Security Centre (NCSC), the FBI, and the Netherlands' General Intelligence and Security Service (AIVD), details how operatives target dissidents, activists, and journalists both inside and outside Iran. The advisory highlights a persistent campaign that combines extensive reconnaissance, social engineering, and destructive capabilities.
Who the advisory aims to protect
The joint advisory identifies the primary victims as dissidents, activists, and journalists whom the Iranian regime perceives as threats. According to the document, Iranian intelligence services have even plotted to kidnap or conduct lethal operations against such individuals internationally. The agencies state that Iran "almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime." This targeting extends beyond Iran's borders, affecting people in other countries who are critical of the government.
The advisory does not name specific victims or provide a tally of confirmed infections. Instead, it serves as a warning to potential targets and their employers, urging heightened vigilance against social engineering tactics. The three agencies emphasize that the campaign is ongoing and that Iranian operatives are actively seeking to compromise Windows machines.
How the attackers make first contact
Before initiating contact, Iranian operatives perform extensive research on their targets, according to the advisory. They gather personal details from social media and other public sources to craft convincing personas. The attackers then reach out via social media platforms, posing either as someone the victim already knows or as technical support for the platform the victim is using. Through extended conversation, they work to lower the victim's guard and build trust.
Once rapport is established, the operative attempts to share the Chosen Brick malware, often disguised as a legitimate file or update. The advisory notes that this social engineering approach relies on human interaction rather than technical exploits, making awareness a critical defense.
What Chosen Brick can do once inside
Chosen Brick is designed primarily for the Windows platform and possesses a wide range of spying and destructive capabilities. According to the advisory, the malware can enumerate running processes and system information, capture screen content, and activate the microphone to record audio. It can also steal data from Telegram and WhatsApp by extracting information from web browsers, as well as pilfer email content. Furthermore, the malware can download additional files and payloads, delete files, and ultimately wipe the entire computer system.
The operatives control the malware through Telegram, using the messaging app as a command-and-control channel. This allows them to issue instructions and receive exfiltrated data while blending in with normal network traffic. The advisory notes that the malware's ability to wipe systems makes it not just a spying tool but also a destructive weapon.
What the agencies recommend
The advisory stresses that the best defense against Chosen Brick is awareness of social engineering tactics. However, it also lists several technical mitigations that can reduce the risk of compromise. These include following NCSC advice on staying safe online, keeping all devices up-to-date (ideally through automatic updates), using antivirus software, and not disabling SmartScreen warnings on file downloads.
Additionally, the agencies recommend enabling phishing-resistant MFA, ensuring devices are managed with appropriate controls, turning on email scanning, deploying endpoint and network monitoring, and conducting a search for indicators of compromise (IoCs). The advisory does not provide specific IoCs in the public text, but organizations are urged to check for signs of Chosen Brick activity.
— The UK National Cyber Security Centre, the FBI, and the Netherlands' General Intelligence and Security Service (AIVD), in a joint advisory
Why Iran uses cyber operations
The advisory states that Iran "almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists." It further notes that in some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, whom they perceive as enemies of the regime. This context underscores the severity of the threat and the importance of the advisory's recommendations.
The joint nature of the advisory—involving the UK, US, and Dutch agencies—reflects a coordinated international effort to expose and counter Iranian cyber activities. The agencies do not attribute the campaign to a specific group within Iran, but they clearly link it to state interests.
Technical mitigations in detail
Beyond general awareness, the advisory provides a set of technical measures that organizations and individuals can implement. These include:
- Follow NCSC advice on staying safe online.
- Keep all devices up-to-date, ideally through automatic updates.
- Use antivirus software.
- Do not disable SmartScreen warnings on file downloads.
- Enable phishing-resistant MFA.
- Ensure devices are managed with appropriate controls.
- Turn on email scanning.
- Deploy endpoint and network monitoring.
- Conduct a search for IoCs.
While these steps are not specific to Chosen Brick, they collectively harden an environment against common attack vectors, including social engineering and malware execution. The advisory emphasizes that no single measure is sufficient; a layered approach is necessary.
What this means for potential targets
For journalists, activists, and dissidents—especially those critical of the Iranian government—the advisory serves as a stark reminder of the risks they face online. The combination of social engineering and destructive malware means that a single mistake can lead to data theft, system wipe, and potentially physical harm. The agencies urge individuals to be suspicious of unsolicited contacts, even from seemingly familiar sources, and to verify identities through separate channels.
Organizations that employ or support such individuals should also take note. The advisory's recommendations for endpoint monitoring, email scanning, and MFA are particularly relevant for newsrooms, NGOs, and human rights groups. By implementing these controls, they can better protect their staff and sources from targeted attacks.
Broader implications for cybersecurity
The Chosen Brick campaign illustrates how state-sponsored actors continue to leverage social engineering and legitimate platforms like Telegram and WhatsApp for malicious purposes. It also highlights the challenges of defending against targeted attacks that rely on human interaction rather than software vulnerabilities. As the advisory notes, awareness and basic hygiene remain the first line of defense.
For the cybersecurity community, the joint advisory is a call to action to share threat intelligence and improve detection capabilities. The fact that three major agencies collaborated on this warning suggests that the threat is considered significant and persistent. While the advisory does not provide technical indicators, it arms defenders with knowledge of the tactics, techniques, and procedures (TTPs) used by the attackers.
Reporting based on original coverage from TechRadar.
Sources
- TechRadar Original source
Continue Reading
Radaris loses grip on its domains
A New Jersey court has ordered 14 Radaris-linked domains transferred to Atlas in a default judgment over Daniel's Law violations.
Three Clusters Hit Russian Firms
Kaspersky details NightEagle, Hacking Cat and Toy Ghouls deploying backdoors, ransomware and wipers against Russian enterprises.
Premier Medical Group Breach Hits 280,000
A New York healthcare provider says attackers accessed patient files on June 14, exposing medical and personal data for 282,075 people.