Security agencies in the United States, United Kingdom, and the Netherlands have exposed an Iranian cyber espionage campaign that uses carefully prepared social engineering attacks to spy on dissidents, activists, and journalists.
The operation relies on Windows malware known as CHOSEN BRICK. The FBI tracks malware from the same family as HEAVYGRAM and has linked its use to Iran’s Ministry of Intelligence and Security.
Rather than immediately sending suspicious attachments to potential victims, the attackers research their targets and attempt to gain their trust. They contact people through messaging services such as Telegram and WhatsApp while pretending to be known contacts or technical support representatives.
The conversations can continue while the attackers build credibility before introducing a malicious file. The file is designed to match the story being used in the conversation, making the request appear more convincing.
Some victims have been offered applications disguised as legitimate software, including Telegram, KeePass, Norton Antivirus, Pictory and RunwayML. In one particularly unusual case, the attackers presented a malicious file as MRI scan results.
Opening the file displays content intended to maintain the deception while malware is installed in the background.
Investigators have only observed CHOSEN BRICK targeting Windows systems. Once installed, it can establish persistence so that it continues operating after the computer is restarted.
Telegram also plays another role after infection. The malware can communicate with Telegram bots controlled by the attackers, allowing commands and stolen information to move through the service. Investigators found that individual victims could be assigned separate Telegram bot IDs.
CHOSEN BRICK provides extensive surveillance capabilities. It can capture screenshots, activate a computer’s microphone, collect emails and files, and obtain Telegram and WhatsApp data stored through web browsers. Attackers can also gather information about running processes and the infected system.
The malware is capable of downloading additional malicious files and deleting information. At least one analyzed version also contained functionality that could wipe data from the computer.
Authorities warned that the information collected can reveal considerably more than account credentials. Screenshots, communications and other stolen data may expose a person’s contacts, movements and daily routines.
Some information obtained from previous victims has later appeared on pro-Iranian leak websites, according to the joint advisory.
The attackers have also demonstrated an interest in bypassing workplace security. When attempts to compromise a corporate computer fail or appear likely to trigger security controls, they may encourage the target to continue the interaction on a personal device instead.
UK authorities assess that Iran “almost certainly” uses cyber operations to support efforts against individuals it considers threats. The FBI similarly says actors working on behalf of Iran’s intelligence ministry are likely using the malware for intelligence collection, data leaks and reputational harm.
The newly released advisory is intended to help potential targets and security teams recognize the campaign. CHOSEN BRICK remains an active concern, with authorities warning that its combination of personalized social engineering and persistent device surveillance can put both targeted individuals and people connected to them at risk.