Iranian State Hackers Deploy CHOSEN BRICK Malware to Spy on Dissidents via Telegram
A joint advisory from the NCSC, FBI, and AIVD warns that Iranian state-sponsored cyber actors have been targeting dissidents, activists, and journalists worldwide since at least 2025. Attackers pose as trusted contacts or technical support on WhatsApp and Telegram to trick victims into running a malicious Windows file disguised as a legitimate application. Once executed, the CHOSEN BRICK malware silently collects screen activity, audio, emails, and messages, relaying stolen data to attacker-controlled Telegram bots or cloud storage. The malware establishes persistence via Windows registry run keys and evades detection by adding itself to Microsoft Defender exclusions. Capabilities including file deletion and device wiping have been confirmed, raising serious physical safety concerns for targeted individuals.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in