US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
Chosen Brick is a Windows malware family used by Iranian state-sponsored actors to surveil dissidents, activists, and journalists globally. Active since at least 2025, it harvests personal data such as contacts, emails, and social media messages to track individuals. Infection typically begins via messaging platforms like WhatsApp and Telegram, using social engineering to deliver malicious files disguised as legitimate utilities or medical documents. The malware establishes persistence through registry keys, evades Microsoft Defender by adding exclusions, and uses Telegram bots for command-and-control and data exfiltration. It can capture screenshots, record audio, steal browser chat data, deploy secondary payloads, and wipe data on command. The FBI and allied agencies have published advisories detailing its use and infrastructure. No automated lateral movement is observed, but operators can manually expand access via secondary payloads.
AI Analysis
Technical Summary
Chosen Brick is a surveillance malware targeting Windows systems, deployed by Iranian state cyber actors since at least 2025. It primarily targets dissidents, activists, and journalists worldwide to collect personal data supporting state repression. Infection vectors include social engineering on messaging platforms such as WhatsApp and Telegram, delivering weaponized files disguised as legitimate software or fake medical documents. Upon execution, it establishes persistence via registry Run keys and attempts to evade detection by adding exclusions in Microsoft Defender. For command-and-control, it uses unique Telegram bot IDs per infected host, leveraging Telegram infrastructure and cloud storage for data exfiltration. Capabilities include screenshot capture, microphone audio recording, browser chat data theft, email theft, secondary payload deployment, and destructive commands like data wiping. While lacking automated lateral movement, operators can manually expand access through additional payloads. The FBI and allied agencies have publicly documented this malware and its abuse of Telegram for C&C.
Potential Impact
The malware enables Iranian state actors to conduct extensive surveillance on targeted individuals, harvesting sensitive personal data that can be used to track locations and life patterns. This supports state-sponsored repression, including harassment via posting stolen information on pro-Iranian leak sites. The malware's capabilities to capture screenshots, record audio, steal emails and chat data, and deploy destructive commands pose significant privacy and security risks to victims. The use of Telegram for C&C and data exfiltration complicates detection and attribution. Although no automated lateral movement is present, manual expansion of access increases the threat's persistence and potential impact.
Mitigation Recommendations
No official patch or remediation is indicated for the malware itself, as it is a threat actor tool rather than a software vulnerability. Defenders should be aware that infection vectors include social engineering via messaging platforms, often targeting corporate devices first and then personal devices if blocked. Security controls should focus on user awareness training to recognize social engineering attempts and suspicious file attachments. Endpoint protection should monitor for persistence mechanisms such as registry Run keys and unusual Microsoft Defender exclusions. Network monitoring for unusual Telegram bot communications may help detect infections. The FBI and allied agencies have published advisories with further guidance; organizations should consult these for detailed mitigation strategies. Since this is malware deployed by threat actors, remediation focuses on detection, prevention of initial compromise, and incident response rather than patching software.
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
Description
Chosen Brick is a Windows malware family used by Iranian state-sponsored actors to surveil dissidents, activists, and journalists globally. Active since at least 2025, it harvests personal data such as contacts, emails, and social media messages to track individuals. Infection typically begins via messaging platforms like WhatsApp and Telegram, using social engineering to deliver malicious files disguised as legitimate utilities or medical documents. The malware establishes persistence through registry keys, evades Microsoft Defender by adding exclusions, and uses Telegram bots for command-and-control and data exfiltration. It can capture screenshots, record audio, steal browser chat data, deploy secondary payloads, and wipe data on command. The FBI and allied agencies have published advisories detailing its use and infrastructure. No automated lateral movement is observed, but operators can manually expand access via secondary payloads.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Chosen Brick is a surveillance malware targeting Windows systems, deployed by Iranian state cyber actors since at least 2025. It primarily targets dissidents, activists, and journalists worldwide to collect personal data supporting state repression. Infection vectors include social engineering on messaging platforms such as WhatsApp and Telegram, delivering weaponized files disguised as legitimate software or fake medical documents. Upon execution, it establishes persistence via registry Run keys and attempts to evade detection by adding exclusions in Microsoft Defender. For command-and-control, it uses unique Telegram bot IDs per infected host, leveraging Telegram infrastructure and cloud storage for data exfiltration. Capabilities include screenshot capture, microphone audio recording, browser chat data theft, email theft, secondary payload deployment, and destructive commands like data wiping. While lacking automated lateral movement, operators can manually expand access through additional payloads. The FBI and allied agencies have publicly documented this malware and its abuse of Telegram for C&C.
Potential Impact
The malware enables Iranian state actors to conduct extensive surveillance on targeted individuals, harvesting sensitive personal data that can be used to track locations and life patterns. This supports state-sponsored repression, including harassment via posting stolen information on pro-Iranian leak sites. The malware's capabilities to capture screenshots, record audio, steal emails and chat data, and deploy destructive commands pose significant privacy and security risks to victims. The use of Telegram for C&C and data exfiltration complicates detection and attribution. Although no automated lateral movement is present, manual expansion of access increases the threat's persistence and potential impact.
Defensive Guidance
No official patch or remediation is indicated for the malware itself, as it is a threat actor tool rather than a software vulnerability. Defenders should be aware that infection vectors include social engineering via messaging platforms, often targeting corporate devices first and then personal devices if blocked. Security controls should focus on user awareness training to recognize social engineering attempts and suspicious file attachments. Endpoint protection should monitor for persistence mechanisms such as registry Run keys and unusual Microsoft Defender exclusions. Network monitoring for unusual Telegram bot communications may help detect infections. The FBI and allied agencies have published advisories with further guidance; organizations should consult these for detailed mitigation strategies. Since this is malware deployed by threat actors, remediation focuses on detection, prevention of initial compromise, and incident response rather than patching software.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/","fetched":true,"fetchedAt":"2026-09-16T12:01:39.424Z","wordCount":1078}
Threat ID: 6aaa852355bf5e2cf5909689
Added to database: 09/16/2026, 12:01:39 UTC
Last enriched: 09/16/2026, 12:01:45 UTC
Last updated: 09/16/2026, 22:18:02 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.