Security agencies have revealed new details about CHOSEN BRICK, a Windows malware family used by Iranian state-linked hackers to maintain access to computers and collect sensitive information from selected targets.

 

 

The UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD linked the campaign to Iranian state cyber actors. The FBI assesses that operators working on behalf of Iran’s Ministry of Intelligence and Security are responsible for related activity.

CHOSEN BRICK has been observed targeting people around the world since at least 2025. The FBI tracks related malware as HEAVYGRAM and has identified versions used in operations dating back to fall 2023.

The campaign has primarily focused on Iranian dissidents, journalists critical of the Iranian government, activists, and members of organizations whose views conflict with Iranian government narratives.

Attackers do not rely on indiscriminate malware distribution. Instead, they research individual targets and use personalized social engineering to increase the likelihood that a malicious file will be opened.

Initial contact can take place through Telegram or WhatsApp. Attackers may impersonate someone the victim trusts or pretend to provide technical support. After establishing credibility, they send a file designed to fit the conversation.

The disguises vary considerably. Authorities have identified malicious files presented as Telegram, KeePass, Norton Antivirus, Pictory, RunwayML, and other legitimate applications. One lure was even designed to appear as MRI scan results.

When opened, the malicious file can display convincing content matching the attacker’s story while secretly installing CHOSEN BRICK in the background.

The malware establishes persistence on Windows so it can continue operating after the computer is restarted. Investigators also observed attempts to create Microsoft Defender exclusions for selected files and folders, reducing the likelihood that the malware will be detected.

Once active, CHOSEN BRICK provides extensive surveillance capabilities. Attackers can capture screenshots, collect files and emails, activate the computer’s microphone, and obtain information associated with Telegram and WhatsApp sessions accessed through web browsers.

The malware can also download additional files and receive instructions remotely. Telegram bots are used as part of its command-and-control infrastructure, allowing infected computers to communicate with systems controlled by the attackers. Some versions contain destructive functionality as well, including the ability to delete files.

Authorities warn that the collected information can expose far more than passwords or documents. Messages, contacts, screenshots and other data can reveal relationships, movements and everyday routines.

Information stolen from some previous victims has later appeared on pro-Iranian leak websites, according to the agencies.

The operators may also adapt when corporate security interferes with an attack. If compromising a work computer proves difficult, investigators say targets can be encouraged to continue the conversation or open files on personal devices instead.

All observed CHOSEN BRICK infections described in the advisory have targeted Windows. The agencies have released technical indicators and mitigation guidance to help potential targets and security teams identify infections and reduce the risk of compromise.

Leave a Reply