Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Iranian Spies Employ Chosen Brick Malware to Steal Data from Windows Machines




Iranian state cyber actors have been using the Chosen Brick data-stealing malware to infiltrate and steal sensitive information from Windows machines. This malicious software has been employed to target individuals deemed enemies of the regime, including dissidents, activists, and journalists. The Chosen Brick malware operates by sending phishing messages and downloading additional malware, allowing the attackers to gather intelligence and disrupt the operations of their enemies. Organizations are advised to take immediate action to protect their devices and data, including circulating the warning with staff who may be targeted and providing assistance to affected organizations.

  • Iranian state cyber actors are using the Chosen Brick malware to infiltrate and steal sensitive information from Windows machines.
  • The malware is used to target individuals deemed enemies of the regime, including dissidents, activists, and journalists.
  • The Chosen Brick malware sends phishing messages, allowing attackers to obtain personal data, such as contacts, emails, and social media messages.
  • The malware can also enumerate running processes, capture screen and audio content, and wipe the computer system.
  • Western governments are warning of the ongoing threat posed by Iranian state cyber actors, who have been linked to high-profile cyberattacks.
  • Organizations are advised to take immediate action to protect their devices and data, including investigating instances of Chosen Brick malware and providing assistance to affected organizations.



  • In a disturbing turn of events, Iranian state cyber actors have been found to be utilizing the Chosen Brick data-stealing malware to infiltrate and pilfer sensitive information from Windows machines. This malicious software, which has been in use since at least 2025, has been employed by Iranian intelligence services to target individuals deemed enemies of the regime, including dissidents, activists, and journalists.

    According to a recent security advisory issued by the US, UK, and Netherlands' General Intelligence and Security Service (AIVD), Chosen Brick has been used to compromise the personal devices of individuals, thereby allowing the Iranian spies to obtain their contacts, emails, and social media messages. These stolen data points enable the attackers to track the movements of the targeted individuals, thereby facilitating the Iranian regime's efforts to suppress dissent.

    The Chosen Brick malware operates by sending phishing messages to the targeted individuals, which appear to come from trusted sources. Upon receipt of the message, the victim is convinced to download and open a malicious file, which then executes without their knowledge or consent. The malware persists on the device even after a reboot, and it establishes connections with Telegram for command-and-control communications using a victim-specific bot.

    In addition to its ability to steal data, the Chosen Brick malware also includes features that enable it to enumerate running processes and system information, capture screen and audio content, and wipe the computer system. While it has not yet been observed to automate lateral movement across the network, it is technically possible, according to the advisory.

    The Western governments' warning about the Chosen Brick malware serves as a reminder of the ongoing threat posed by Iranian state cyber actors. These actors have been linked to a series of high-profile cyberattacks, including disruptions to American water utilities and a suspected cyberattack on a small UK power plant.

    The Iranian regime's use of cyber warfare as a tool to suppress dissent and opposition is a growing concern. The Chosen Brick malware is just one example of the tactics employed by Iranian cyber actors to gather intelligence and disrupt the operations of their enemies.

    In light of this threat, organizations are advised to take immediate action to protect their devices and data. This includes circulating the warning with staff who may be targeted and supporting them in checking their personal devices. IT providers are also recommended to investigate any instances of Chosen Brick malware and provide assistance to affected organizations.

    The Chosen Brick malware serves as a stark reminder of the importance of cybersecurity and the need for organizations to stay vigilant in the face of evolving threats. As the landscape of cyber warfare continues to shift, it is essential that individuals and organizations remain informed and take proactive steps to protect themselves from these types of threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Iranian-Spies-Employ-Chosen-Brick-Malware-to-Steal-Data-from-Windows-Machines-ehn.shtml

  • https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646


  • Published: Tue Sep 15 13:29:47 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us