discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Iranian state-linked hackers are using CHOSEN BRICK Windows malware to spy on dissidents, activists, and journalists worldwide. The malware collects email, Telegram, and WhatsApp communications, takes screenshots, and records audio.

By Bill Toulas·Sep 16·bleepingcomputer.com·2 min read

Intelligence analysis by Qwen 2.5 (3B)

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Image: bleepingcomputer.com

Iranian hackers are using CHOSEN BRICK malware to spy on dissidents, activists, and journalists. The malware collects sensitive data and exfiltrates it through Telegram or cloud services.

Why it matters

This story highlights the threat of cyber espionage and the need for organizations to protect against sophisticated malware.

Iranian hackers are using a sneaky computer program called CHOSEN BRICK to spy on people who speak out against the government. The program steals their emails, messages, and pictures, and sends them to bad guys who work for the government.

Analysis

{"heading":"The CHOSEN BRICK Malware: Features and Functionality","subheading":"Understanding the CHOSEN BRICK malware's capabilities and how it operates.","paragraph_1":"CHOSEN BRICK is a Windows malware strain that has been used by Iranian state-linked hackers to target dissidents, activists, and journalists worldwide. The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio.","paragraph_2":"The threat actor primarily targeted individuals in the U.S., U.K., and the Netherlands, whose cybersecurity agencies published a joint advisory with the FBI. The malware is often disguised as legitimate applications, such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass, and others.","paragraph_3":"The malware adds Microsoft Defender exclusions to evade detection and connects to a unique Telegram bot that matches the victim's ID and provides command-and-control (C2). Once launched, CHOSEN BRICK can perform the following actions: collect system information, enumerate running processes, capture screenshots, record audio through the microphone, steal email content, steal Telegram or WhatsApp browser data, download additional payloads to 'C:\Windows \SysWOW64', delete files, and wipe the entire host system.","paragraph_4":"The stolen data is exfiltrated through Telegram or cloud services like VultrObjects and StorjShare, while newer CHOSEN BRICK variants route traffic through SOCKS5 proxies to conceal the activity. The advisory notes that the stolen data sometimes ends up on pro-Iranian leak sites, serving as a form of harassment and increasing the physical risk for dissidents abroad.","paragraph_5":"The advisory notes that the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime. Potential victims and organizations should inspect Registry Run entries for suspicious entries, search logs for indicators of compromise (IoCs) shared in the advisory, and investigate unexpected connections to Telegram's API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies as suspicious.","paragraph_6":"The advisory notes that the stolen data sometimes ends up on pro-Iranian leak sites, serving as a form of harassment and increasing the physical risk for dissidents abroad. The advisory notes that the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime. Potential victims and organizations should inspect Registry Run entries for suspicious entries, search logs for indicators of compromise (IoCs) shared in the advisory, and investigate unexpected connections to Telegram's API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies as suspicious."}

Key points

  • Iranian hackers use CHOSEN BRICK malware to spy on dissidents, activists, and journalists.
  • The malware collects sensitive data and exfiltrates it through Telegram or cloud services.
  • The Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals perceived as enemies of the regime.
  • Potential victims and organizations should inspect Registry Run entries for suspicious entries and investigate unexpected connections to Telegram's API, Backblaze B2, VultrObjects, StorjShare, IPRoyal, and LightningProxies as suspicious.
The Upside

By improving cybersecurity measures, organizations can better protect against such attacks and prevent sensitive data from being stolen.

The Downside

If the Iranian government continues to use such tactics, it could lead to more harm and harassment for dissidents and activists.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecuritymalwareirancyberespionage

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 16, 2026

Source

bleepingcomputer.com

Share

Topics

securitycybersecuritymalwareirancyberespionage

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.