Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Iran's Advanced Surveillance Malware: Unveiling the CHOSEN BRICK Threat




Iran's advanced surveillance malware, CHOSEN BRICK, has been identified as a significant threat by global cybersecurity agencies. This malware family, designed by Iran's intelligence services, enables the tracking and harassment of dissidents, journalists, and activists. To stay safe, users should avoid installing software from links or attachments, keep applications updated, and use active antivirus protection. Organizations should also implement robust cybersecurity measures, including phishing-resistant MFA, application allowlisting, and endpoint monitoring. Protecting personal devices is crucial for high-risk users, and awareness of this threat is essential for preventing state-sponsored cyber attacks.

  • The CHOSEN BRICK malware family is a sophisticated threat designed by Iran's intelligence services to track and harass dissidents, journalists, and activists.
  • The malware collects information on targets' contacts, emails, and social media messages, allowing for tracking of their movements.
  • The attackers use social engineering, reconnaissance, and impersonation to convince victims to open malicious files.
  • The malware sends stolen data through Telegram bots and cloud storage services and can download and install additional malware.
  • Recommended defenses include avoiding software downloads from links or attachments, keeping applications updated, and using active antivirus protection.
  • Individuals and organizations should be vigilant in protecting themselves against state-sponsored cyber threats.



  • The world of cybersecurity has recently been exposed to a new and sophisticated malware family, dubbed CHOSEN BRICK, designed by Iran's intelligence services to track and harass dissidents, journalists, and activists. This malware family has been identified as a significant threat by the UK's National Cyber Security Centre (NCSC), the FBI, and the Netherlands' AIVD, who have jointly released an advisory warning about its dangers.

    The CHOSEN BRICK malware family enables Iranian state cyber actors to collect information on a target's contacts, emails, and social media messages, which could enable tracking of their movements. The malware was first detected in 2025 and has since been used to target individuals worldwide, including in the UK, US, and the Netherlands. According to the advisory, Iranian cyber actors engage with targets via social messaging applications to build rapport prior to attempting to deliver the malware.

    The attackers use a combination of social engineering, reconnaissance, and impersonation to convince their victims to open malicious files. These files are often disguised as legitimate installers or scans, but they contain a convincing decoy screen that helps maintain deception while the real payload installs quietly in the background.

    The malware sends stolen data through Telegram bots and cloud storage services, and it can also download and install additional malware when attackers want more access. CHOSEN BRICK has two distinctive fingerprints, and researchers have found the mutex names "ytyjyujyu" and "noi672pp434awkc12f" in samples.

    The recommended defenses are straightforward. Users should avoid installing software from links or attachments, keep applications updated, use active antivirus protection, and take SmartScreen warnings seriously. Organizations should also use phishing-resistant MFA, application allowlisting, email security, and endpoint monitoring, while checking the published indicators against their own logs.

    Protecting only the corporate laptop may leave the device attackers target next exposed, especially for high-risk users, including journalists, activists, and NGO workers, who should also receive security guidance for their personal devices.

    The threat posed by the CHOSEN BRICK malware family highlights the importance of cybersecurity awareness and the need for individuals and organizations to be vigilant in protecting themselves against state-sponsored cyber threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Irans-Advanced-Surveillance-Malware-Unveiling-the-CHOSEN-BRICK-Threat-ehn.shtml

  • https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html

  • https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/


  • Published: Thu Sep 17 03:50:58 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us