Skip to main content

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

0
High
Malwaremalware
Published: 09/16/2026 (09/16/2026, 12:00:14 UTC)
Source: SecurityWeek

Description

Chosen Brick is a Windows malware family used by Iranian state-sponsored actors to surveil dissidents, activists, and journalists globally. Active since at least 2025, it harvests personal data such as contacts, emails, and social media messages to track individuals. Infection typically begins via messaging platforms like WhatsApp and Telegram, using social engineering to deliver malicious files disguised as legitimate utilities or medical documents. The malware establishes persistence through registry keys, evades Microsoft Defender by adding exclusions, and uses Telegram bots for command-and-control and data exfiltration. It can capture screenshots, record audio, steal browser chat data, deploy secondary payloads, and wipe data on command. The FBI and allied agencies have published advisories detailing its use and infrastructure. No automated lateral movement is observed, but operators can manually expand access via secondary payloads.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 12:01:45 UTC

Technical Analysis

Chosen Brick is a surveillance malware targeting Windows systems, deployed by Iranian state cyber actors since at least 2025. It primarily targets dissidents, activists, and journalists worldwide to collect personal data supporting state repression. Infection vectors include social engineering on messaging platforms such as WhatsApp and Telegram, delivering weaponized files disguised as legitimate software or fake medical documents. Upon execution, it establishes persistence via registry Run keys and attempts to evade detection by adding exclusions in Microsoft Defender. For command-and-control, it uses unique Telegram bot IDs per infected host, leveraging Telegram infrastructure and cloud storage for data exfiltration. Capabilities include screenshot capture, microphone audio recording, browser chat data theft, email theft, secondary payload deployment, and destructive commands like data wiping. While lacking automated lateral movement, operators can manually expand access through additional payloads. The FBI and allied agencies have publicly documented this malware and its abuse of Telegram for C&C.

Potential Impact

The malware enables Iranian state actors to conduct extensive surveillance on targeted individuals, harvesting sensitive personal data that can be used to track locations and life patterns. This supports state-sponsored repression, including harassment via posting stolen information on pro-Iranian leak sites. The malware's capabilities to capture screenshots, record audio, steal emails and chat data, and deploy destructive commands pose significant privacy and security risks to victims. The use of Telegram for C&C and data exfiltration complicates detection and attribution. Although no automated lateral movement is present, manual expansion of access increases the threat's persistence and potential impact.

Defensive Guidance

No official patch or remediation is indicated for the malware itself, as it is a threat actor tool rather than a software vulnerability. Defenders should be aware that infection vectors include social engineering via messaging platforms, often targeting corporate devices first and then personal devices if blocked. Security controls should focus on user awareness training to recognize social engineering attempts and suspicious file attachments. Endpoint protection should monitor for persistence mechanisms such as registry Run keys and unusual Microsoft Defender exclusions. Network monitoring for unusual Telegram bot communications may help detect infections. The FBI and allied agencies have published advisories with further guidance; organizations should consult these for detailed mitigation strategies. Since this is malware deployed by threat actors, remediation focuses on detection, prevention of initial compromise, and incident response rather than patching software.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/","fetched":true,"fetchedAt":"2026-09-16T12:01:39.424Z","wordCount":1078}

Threat ID: 6aaa852355bf5e2cf5909689

Added to database: 09/16/2026, 12:01:39 UTC

Last enriched: 09/16/2026, 12:01:45 UTC

Last updated: 09/16/2026, 22:18:02 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses