Iranian Hackers Deploy CHOSEN BRICK Malware to Target Activists

Iranian state-linked hackers are using the CHOSEN BRICK Windows malware to conduct surveillance on activists, dissidents, and journalists worldwide, enabling persistent spying and data collection.

Why it matters

This campaign underscores persistent state-sponsored espionage efforts that threaten vulnerable individuals and groups globally by leveraging sophisticated malware for ongoing surveillance.

SOC impact

SOC teams should monitor for indicators related to CHOSEN BRICK malware activity, analyze telemetry for suspicious persistence mechanisms, and assess exposure among assets that could be targeted due to their activist or journalistic roles.

Recommended actions

  1. Identify and inventory systems matching CHOSEN BRICK infection profiles
  2. Monitor network traffic for anomalous data exfiltration patterns
  3. Review logs for signs of persistent unauthorized access
  4. Correlate threat intelligence on Iranian state-sponsored malware with local telemetry
  5. Assess organizational exposure based on user roles and risk profiles

Executive Summary

Iranian state-linked threat actors have been observed deploying a Windows malware strain named CHOSEN BRICK targeting dissidents, activists, and journalists worldwide. The malware facilitates persistent surveillance that enables ongoing data collection from compromised systems. This activity reflects sustained state-sponsored cyber-espionage efforts against monitored individuals, raising operational concerns regarding the protection of high-risk user groups. Security teams must prioritize detection of this specific malware and investigate unusual access patterns that may indicate CHOSEN BRICK presence to mitigate risk and understand the scope of exposure within their environments.

SOC Impact

SOC teams should monitor for indicators related to CHOSEN BRICK malware activity, analyze telemetry for suspicious persistence mechanisms, and assess exposure among assets that could be targeted due to their activist or journalistic roles.

Detection and Exposure Assessment

  • Identify and inventory systems matching CHOSEN BRICK infection profiles
  • Monitor network traffic for anomalous data exfiltration patterns
  • Review logs for signs of persistent unauthorized access
  • Correlate threat intelligence on Iranian state-sponsored malware with local telemetry
  • Assess organizational exposure based on user roles and risk profiles

Why It Matters

This campaign underscores persistent state-sponsored espionage efforts that threaten vulnerable individuals and groups globally by leveraging sophisticated malware for ongoing surveillance.

Source