Iranian state-linked hackers are using a Windows malware strain called CHOSEN BRICK to spy on dissidents, activists and journalists, according to a joint advisory from cybersecurity agencies in the United States, the United Kingdom and the Netherlands, issued alongside the FBI. The agencies warn the campaign has reached victims worldwide, with targets concentrated in those three countries. The malware is built for data theft and espionage.

Once installed, CHOSEN BRICK collects email, Telegram and WhatsApp communications, captures screenshots and records audio. Attacks typically start with social engineering messages on WhatsApp or Telegram in which the hackers pose as trusted contacts or technical support agents. Victims are then persuaded to open malicious files disguised as legitimate applications, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass. The agencies found the hackers sometimes used medical-related lures as well.

The fake installers are presented as apps that should be run on personal devices, a suggestion meant to get around corporate security controls. Each displays an interface that matches the application it claims to be while installing CHOSEN BRICK quietly in the background. The malware holds its position on a system through Windows Registry Run keys, adds Microsoft Defender exclusions to avoid detection, and contacts a Telegram bot tied to the victim's identifier to receive commands.

Stolen information is sent out through Telegram or cloud services including VultrObjects and StorjShare. Newer versions of CHOSEN BRICK route their traffic through SOCKS5 proxies to hide the activity. The advisory notes that exfiltrated data has sometimes appeared on pro-Iranian leak sites, which the agencies describe as a form of harassment that raises the physical danger for dissidents living abroad.

The agencies state that Iran almost certainly uses cyber operations to support the repression of people viewed as threats to the regime, naming dissidents, activists and journalists. They add that Iranian intelligence services have in some cases plotted to kidnap or carry out lethal operations internationally against individuals they consider enemies of the regime.

The advisory directs potential victims and organizations to check Registry Run entries for suspicious items and to search logs for the indicators of compromise it publishes. It also says unexpected connections to Telegram's API, Backblaze B2, VultrObjects, StorjShare, IPRoyal and LightningProxies should be treated as suspicious.

More cybersecurity news from TechManNews.