Executive Summary
Recent intelligence from multiple Western cybersecurity agencies, including the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands General Intelligence and Security Service (AIVD), has confirmed a sophisticated cyber-espionage campaign orchestrated by Iranian state-sponsored actors. The campaign leverages a Windows malware family known as CHOSEN BRICK to conduct targeted surveillance against dissidents, journalists, and activists, primarily in the United Kingdom, United States, and the Netherlands. The threat actors employ advanced social engineering tactics, often impersonating trusted contacts or technical support via WhatsApp and Telegram, to deliver the malware payload. CHOSEN BRICK is engineered for stealth, persistence, and comprehensive data exfiltration, and has been linked to both cyber and physical operations against regime opponents. This report provides a detailed technical analysis of the malware, its tactics, techniques, and procedures (TTPs), observed exploitation in the wild, victimology, and actionable mitigation strategies.
Threat Actor Profile
The campaign is attributed to Iranian state cyber actors, with strong alignment to the group tracked as APT42 (also known as Charming Kitten or Phosphorus). APT42 is notorious for targeting individuals and organizations perceived as threats to the Iranian regime, particularly those involved in activism, journalism, and opposition politics. The group is characterized by its use of highly tailored social engineering, custom malware, and a focus on intelligence gathering. APT42 has a history of leveraging messaging platforms for initial access and command and control (C2), and its operations often support broader Iranian strategic objectives, including physical intimidation and attacks on critical infrastructure.
Technical Analysis of Malware/TTPs
CHOSEN BRICK is a modular Windows malware family designed for stealthy surveillance and data theft. The infection chain typically begins with direct social engineering via WhatsApp or Telegram, where attackers impersonate trusted contacts or technical support personnel. After extensive reconnaissance, victims are lured into downloading malicious files disguised as legitimate software installers or medical documents. Observed lure files include fake installers for Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, as well as medical-themed files such as MRI scan results (e.g., MRI_Scan_Results.pdf.exe).
Upon execution, CHOSEN BRICK performs several actions to ensure persistence and evade detection. It exclusively targets Windows systems, adding exclusions to Microsoft Defender to bypass endpoint protection. Persistence is established via the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ensuring the malware executes at user login and survives system reboots.
For command and control, each infected device communicates with a unique Telegram bot, which facilitates data exfiltration and remote operator control. The malware is capable of enumerating running processes, collecting detailed system information, capturing screenshots, activating the microphone for audio recording, and stealing emails as well as WhatsApp and Telegram data from browsers. It can also delete files, download and execute additional payloads, or wipe the device entirely. Data exfiltration via Telegram bots complicates detection and attribution, as traffic blends with legitimate messaging activity.
Operational security is a hallmark of this campaign. Each victim is assigned a unique bot, preventing cross-attribution and limiting the impact of any single compromise. Stolen data, including screenshots and contact lists, has been observed on pro-Iranian leak sites, indicating a willingness to publicly expose or further exploit victims.
Key indicators of compromise (IOCs) include unauthorized entries in the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, unusual exclusions in Microsoft Defender, outbound connections to Telegram APIs or bots, and the presence of suspicious installer files masquerading as popular software or medical documents.
Exploitation in the Wild
The CHOSEN BRICK campaign has been observed targeting dissidents, journalists, and activists in the United Kingdom, United States, and the Netherlands. Both personal and work devices are at risk, with attackers adapting their approach based on the security posture of the target environment. If organizational devices are well-protected, attackers pivot to personal devices, exploiting weaker security controls.
The impact of successful compromise is significant. The malware enables real-time tracking of victims’ movements and communications, providing intelligence that can be used for further cyber or physical operations, including intimidation, kidnapping, or assassination. There is evidence linking some attacks to broader Iranian campaigns against critical infrastructure, such as water utilities and power plants, although CHOSEN BRICK itself is primarily used for targeted surveillance rather than disruptive attacks.
Victimology and Targeting
Victims of the CHOSEN BRICK campaign are predominantly individuals and organizations perceived as adversaries of the Iranian regime. This includes political dissidents, journalists, human rights activists, and members of the Iranian diaspora. The campaign has a strong geographic focus on the United Kingdom, United States, and the Netherlands, but the TTPs are adaptable and could be deployed against targets in other regions.
The attackers conduct thorough reconnaissance to craft convincing lures, often leveraging publicly available information and social media profiles to impersonate trusted contacts. The use of WhatsApp and Telegram as initial access vectors exploits the trust placed in these platforms and the difficulty of monitoring encrypted communications. The targeting of both personal and work devices increases the likelihood of successful compromise and data exfiltration.
Mitigation and Countermeasures
Organizations and individuals at risk from CHOSEN BRICK should implement a multi-layered defense strategy. Key recommendations include:
Regularly auditing Windows registry keys, particularly HKCU\Software\Microsoft\Windows\CurrentVersion\Run, for unauthorized entries that may indicate persistence mechanisms. Monitoring Microsoft Defender for new or suspicious exclusions, as attackers use this technique to evade detection. Inspecting network traffic for outbound connections to Telegram APIs or bots, which may signal active command and control channels. Conducting regular searches for suspicious installer files, especially those masquerading as popular software or medical documents, and educating users about the risks of downloading files from untrusted sources. Implementing robust endpoint detection and response (EDR) solutions capable of detecting registry modifications, process injection, and unusual network activity. Enforcing strict application whitelisting and user privilege management to limit the execution of unauthorized software. Providing targeted security awareness training for high-risk individuals, emphasizing the dangers of social engineering and the importance of verifying the identity of contacts on messaging platforms. Establishing clear incident response procedures for suspected malware infections, including immediate isolation of affected devices, forensic analysis, and notification of relevant stakeholders. Sharing IOCs and threat intelligence with security teams and updating detection rules to reflect the latest TTPs associated with CHOSEN BRICK.
References
HelpNetSecurity: Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists (https://www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/), The Register: Iranian spies hit Windows machines with Chosen Brick data-stealing malware (https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646), TechRadar: Iran snoops on enemies of the state with Chosen Brick malware (https://www.techradar.com/pro/security/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps), Reddit: US, UK, and Dutch Agencies Warn of Iranian Chosen Brick (https://www.reddit.com/r/pwnhub/comments/1wi9g2h/us_uk_and_dutch_agencies_warn_of_iranian_chosen/), GBHackers: Hackers Disguise CHOSEN BRICK Malware as AI Apps (https://gbhackers.com/chosen-brick-malware/), MITRE ATT&CK: APT42 (https://attack.mitre.org/groups/G1006/)
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify and respond to emerging threats. For more information or to discuss how Rescana can support your cybersecurity strategy, please contact us at info@rescana.com.



