[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXa-BeSTuvZIa5-p798wdU4vPVsTzJp0zYi95x3B1DLg":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"0ab8cdbf-6d80-474e-ac1f-e7bf7a41b7a6","US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware","us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware-f6002a","US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.","US, UK, and Dutch agencies have exposed 'Chosen Brick,' a Windows surveillance malware used by Iranian state actors since at least 2025 to target dissidents, activists, and journalists globally. The malware harvests sensitive data, including contacts, emails, and social media messages, and can exfiltrate information via Telegram and cloud services. Stolen data has been used for harassment and posted on pro-Iranian leak sites.","US, UK, and Dutch agencies warn of Iranian 'Chosen Brick' surveillance malware targeting dissidents.","Cybersecurity and intelligence agencies in the US, UK, and Netherlands have issued a joint advisory warning of a Windows malware family dubbed Chosen Brick, deployed by Iranian state cyber actors to target dissidents, activists, and journalists worldwide. Active since at least 2025, Chosen Brick is leveraged by Iranian operators to harvest contacts, emails, social media messages, and other types of data that can be used to track an individual’s location and life patterns. The agencies noted that the activity directly supports state-sponsored repression against individuals perceived as threats to the regime, with stolen personal information occasionally posted to pro-Iranian leak sites to harass targets. The attack chain typically begins on messaging platforms such as WhatsApp and Telegram. Operators research their targets to build rapport, often posing as acquaintances or platform technical support representatives before delivering weaponized files. Attackers frequently initiate contact through a target’s corporate device. However, if security controls block delivery, the attackers try to shift the interaction to the individual’s personal device to bypass enterprise protections. To trick victims, threat actors disguise malicious installers as legitimate utility software or as fake medical documentation, such as MRI scan results. When opened, the file displays a decoy screen while stealthily executing the malware in the background. Advertisement. Scroll to continue reading. All observed infections have targeted Windows. Upon execution, Chosen Brick establishes persistence across reboots using registry Run keys and attempts to evade local security tools by adding exclusions in Microsoft Defender. For command-and-control (C&C) operations, the malware assigns each infected endpoint a unique Telegram bot ID to maintain operational security and prevent cross-victim contamination. Exfiltration occurs through the Telegram infrastructure and cloud storage services. The FBI has separately published a document describing how Iranian state-sponsored hackers have used Telegram as C&C infrastructure in malware attacks targeting the regime’s opponents. Chosen Brick contains extensive surveillance and destructive capabilities. Operators can capture screenshots, record host audio via the microphone, extract browser-stored chat data, steal emails, deploy secondary malware payloads, and execute commands to wipe data. While the malware lacks automated lateral movement capabilities, its ability to download secondary payloads lets operators expand access manually. Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days Related: US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks DataOpenAI Investigates Report Linking AI Agents to RubyGems AttackMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationTelus Warns Customers of Account BreachesTrezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonAnthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion Latest News Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to TakeoverHackuity Raises $19 Million for AI-Powered Vulnerability Management280,000 Impacted by Premier Medical Group Data BreachChrome, Firefox Updates Patch 115 VulnerabilitiesAcronis Patches Exploited Vulnerability in cPanel Backup PluginEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityOracle Patches 800+ Vulnerabilities in September 2026 Security UpdateMicrosoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveFrank Krieger has been named Chief Information Security Officer at Swap.Geoff Belknap has joined HubSpot as Chief Trust Officer.Zero Networks has named Yossi Dagan as Chief Financial Officer.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fus-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-09-16T12:00:14+00:00","2026-09-16T12:00:22.315627+00:00",9,[18,21,24,26],{"name":19,"type":20},"Iranian state cyber actors","threat_actor",{"name":22,"type":23},"Telegram","product",{"name":25,"type":23},"Microsoft Defender",{"name":27,"type":23},"WhatsApp","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":28,"icon":30,"name":31,"slug":32},null,"Nation-state","nation-state",[34,39,41,46],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":40},{"id":28,"icon":30,"name":31,"slug":32},{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":47},{"id":48,"icon":30,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,55,59,62,65,68,71,74,77,80,83,86],{"type":45,"value":53,"context":54},"Chosen Brick","Name of the Iranian state-sponsored surveillance malware.",{"type":56,"value":57,"context":58},"mitre_attack","T1059.003","Execution of PowerShell scripts for malware execution.",{"type":56,"value":60,"context":61},"T1547.001","Registry Run Keys \u002F Startup Folder for persistence.",{"type":56,"value":63,"context":64},"T1071.001","Web Protocols for C2 communication (Telegram).",{"type":56,"value":66,"context":67},"T1041","Exfiltration Over C2 Channel (Telegram).",{"type":56,"value":69,"context":70},"T1113","Screen Capture.",{"type":56,"value":72,"context":73},"T1125","Video Capture (Implied by audio recording).",{"type":56,"value":75,"context":76},"T1115","Clipboard Data.",{"type":56,"value":78,"context":79},"T1056.001","Keylogging.",{"type":56,"value":81,"context":82},"T1020","Automated Exfiltration.",{"type":56,"value":84,"context":85},"T1070.004","File Deletion.",{"type":56,"value":87,"context":88},"T1053.005","Scheduled Task \u002F Job."]