Government officials from the UK, U.S, and the Netherlands have reported a new sypware for the Windows operating system called “CHOSEN BRICK.” In a joint report, they warned that this malware has been used by Iranian intelligence agencies to hack and spy on dissidents, activists, and journalists worldwide.
The UK’s National Cyber Security Center (NCSC) and its international counterparts have issued a warning regarding phishing attacks and cyber-espionage by Iranian agents. The CHOSEN BRICK malware family is used to gather information from targets globally, including screenshots and messaging history. This malware allows attackers to collect data on victims’ contacts, emails, and social media messages. Hackers can also activate the computer’s camera and microphone for ambient eavesdropping.
Interestingly, these attacks begin with social engineering and deployment of messages – usually via Telegram or Whatsapp – where attackers pose as trusted contacts. By impersonating trusted individuals or technical support experts, they persuade victims to run files that are often disguised as legitimate software or medical documents.
Once the victim has downloaded the malicious file, CHOSEN BRICK is installed, allowing the attacker to access sytem information, capture screenshots, steal email content, delete files, and even wipe the entire host system.
The UK’s NCSC released guidance for people who may be perceived as threats to Iran, including dissidents, activists, and journalists. The advisory noted that some of the stolen data had been published on pro-Iran leaker websites. The NCSC Director of Operations stated: “We will continue to call out malicious cyber activities by the Iranian state and help communities by offering practical advice to strengthen their personal security online.”





