[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb_rbx1wtRBy3D1eQpztpi-Nm3qu3NCwQ9QACc9rfDN0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"7f40a942-43d1-4415-8387-11b294d1b380","iranian-chosen-brick-malware-targets-dissidents-and-activists-worldwide","0ab8cdbf-6d80-474e-ac1f-e7bf7a41b7a6","Iranian 'Chosen Brick' Malware Targets Dissidents and Activists Worldwide","Iranian state actors deployed 'Chosen Brick,' a Windows-based surveillance malware, to systematically harvest sensitive personal data — including contacts, emails, and social media messages — from dissidents, journalists, and activists. The stolen information was weaponized for harassment campaigns and published on pro-Iranian leak sites, demonstrating how surveillance malware can cause real-world physical and reputational harm beyond the digital realm. At-risk individuals, particularly those opposing authoritarian regimes, often lack the technical awareness to recognize sophisticated spyware infections on their devices. This case underscores that state-sponsored threat actors increasingly target civil society, not just government or corporate networks, making broad security awareness and device hygiene critical for vulnerable populations.","**Immediate actions:**\n- Audit and harden Windows endpoints used by journalists, activists, and dissidents by removing unnecessary applications and enabling application allowlisting.\n- Run reputable anti-malware and endpoint detection tools to scan for indicators of compromise associated with 'Chosen Brick.'\n- Revoke and rotate credentials for email, social media, and cloud accounts on any potentially compromised devices.\n\n**Long-term improvements:**\n- Deliver targeted security awareness training to at-risk communities (journalists, activists, NGOs) covering phishing, suspicious attachments, and signs of device compromise.\n- Implement end-to-end encrypted communication tools (e.g., Signal) as the default for sensitive conversations to limit data harvested by surveillance malware.\n- Establish a device replacement and secure rebuild program for high-risk individuals whose endpoints may be persistently compromised.\n\n**Detection measures:**\n- Monitor outbound network traffic for anomalous data exfiltration to Telegram bots or unauthorized cloud services.\n- Deploy endpoint detection and response (EDR) solutions configured to alert on unauthorized access to contact lists, email clients, and messaging applications.\n- Enable centralized logging of process execution and network connections to facilitate rapid forensic investigation if compromise is suspected.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 13: Network Monitoring and Defense","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 SC-8: Transmission Confidentiality and Integrity","NIST SP 800-150: Guide to Cyber Threat Information Sharing","GDPR Article 32: Security of Processing (for EU-based individuals affected)","GDPR Article 33: Notification of a Personal Data Breach","ITIL: Information Security Management — Threat & Vulnerability Management","published","2026-09-16T12:20:21.766563+00:00","2026-09-16T12:20:21.643+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fus-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware\u002F","us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware-f6002a","US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"ec7b36d6-e1b3-4bc2-aadd-dd6a5763c2b4","2026-09-16","afternoon","ThreatNoir Afternoon Brief — September 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-16\u002Fthreatnoir-afternoon-brief-2026-09-16.mp3"]