Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Iranian state-linked hackers are deploying a Windows malware strain named CHOSEN BRICK to conduct espionage on dissidents, activists, and journalists globally. The malware is used to spy on targeted individuals, indicating a focus on surveillance rather than widespread disruption or destruction.
AI Analysis
Technical Summary
CHOSEN BRICK is a Windows-based malware strain attributed to Iranian state-linked threat actors. It is employed primarily to spy on specific targets such as dissidents, activists, and journalists worldwide. The malware facilitates covert surveillance operations by these actors, consistent with state-sponsored espionage objectives. No detailed technical information or exploitation methods are provided in the available data.
Potential Impact
The malware enables Iranian state-linked hackers to conduct targeted espionage on individuals of interest, potentially compromising their privacy and security. This could lead to unauthorized data collection, monitoring of communications, and other forms of surveillance. There is no information indicating broader system compromise or disruption beyond targeted spying.
Mitigation Recommendations
No patch or remediation details are provided. Since this is malware used in targeted attacks, standard defensive measures such as endpoint protection, user awareness, and network monitoring for suspicious activity are advisable. Specific mitigation guidance should be sought from vendor advisories or threat intelligence updates if available.
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Description
Iranian state-linked hackers are deploying a Windows malware strain named CHOSEN BRICK to conduct espionage on dissidents, activists, and journalists globally. The malware is used to spy on targeted individuals, indicating a focus on surveillance rather than widespread disruption or destruction.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CHOSEN BRICK is a Windows-based malware strain attributed to Iranian state-linked threat actors. It is employed primarily to spy on specific targets such as dissidents, activists, and journalists worldwide. The malware facilitates covert surveillance operations by these actors, consistent with state-sponsored espionage objectives. No detailed technical information or exploitation methods are provided in the available data.
Potential Impact
The malware enables Iranian state-linked hackers to conduct targeted espionage on individuals of interest, potentially compromising their privacy and security. This could lead to unauthorized data collection, monitoring of communications, and other forms of surveillance. There is no information indicating broader system compromise or disruption beyond targeted spying.
Defensive Guidance
No patch or remediation details are provided. Since this is malware used in targeted attacks, standard defensive measures such as endpoint protection, user awareness, and network monitoring for suspicious activity are advisable. Specific mitigation guidance should be sought from vendor advisories or threat intelligence updates if available.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/","fetched":true,"fetchedAt":"2026-09-16T21:01:46.382Z","wordCount":738}
Threat ID: 6aab03ba55bf5e2cf5272249
Added to database: 09/16/2026, 21:01:46 UTC
Last enriched: 09/16/2026, 21:01:51 UTC
Last updated: 09/17/2026, 03:41:51 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.