logo

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

ID: b5a3ec11-8324-592a-8390-73a9bac6f915

STIX ID: report--b5a3ec11-8324-592a-8390-73a9bac6f915

Feed Name: Help Net Security

Threat Score
87/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Sinisa Markovic

...
...

**Executive summary:** Western intelligence agencies warn that Iranian state actors are operating the CHOSEN BRICK campaign targeting dissidents, activists, and journalists in the UK, US, and the Netherlands; attackers use WhatsApp/Telegram social-engineering lures to deliver Windows malware that persists via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key, adds Microsoft Defender exclusions, communicates via Telegram bots, and can capture screenshots, audio, browser-stored messaging data, emails, download further malware, or wipe devices — capabilities that have enabled tracking and public leaks of victim data and present risks including targeting for kidnapping or lethal operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.