Iranian State Hackers Deploy New CHOSEN BRICK Malware Against Dissidents and Journalists
Government agencies have issued a warning that Iranian state-linked threat actors are using a previously undocumented Windows malware strain called CHOSEN BRICK in surveillance operations against dissidents, activists, and journalists globally, according to a report from BleepingComputer.
What was reported
Per the advisory, the malware is being used specifically for espionage against individuals rather than broad enterprise targeting — a pattern consistent with prior Iranian state-linked operations against civil society figures. Technical details on the malware's capabilities, delivery mechanism, and specific attribution to a named threat group were not detailed in the available reporting.
Why it matters for defenders
While this campaign targets individuals — dissidents, activists, and journalists — rather than corporations, it's relevant to any organization that supports, employs, or provides services to at-risk populations, including NGOs, media outlets, legal aid groups, and diaspora communities. State-sponsored spyware campaigns against civil society also frequently reuse infrastructure and tradecraft that later surfaces in more conventional intrusions, making early visibility valuable.
What defenders should watch for
- Monitor for unusual Windows process behavior, persistence mechanisms, and outbound connections on endpoints belonging to high-risk individuals (journalists, activists, NGO staff).
- Review phishing and social-engineering attempts targeting personal or organizational accounts, a common initial-access vector in Iranian state-linked campaigns.
- Watch for anomalous scheduled tasks, registry run-key modifications, or unsigned binaries executing from user-writable directories, which are common tradecraft in espionage-focused malware.
- Organizations supporting at-risk individuals should consider hardening endpoint logging and enabling threat-hunting visibility for this population specifically.
Developing story
Technical indicators of compromise and a detailed malware analysis for CHOSEN BRICK were not available at the time of this writing. This is a developing story based on a government advisory reported by BleepingComputer; we will update our coverage as more technical detail, IOCs, or a formal CVE association (if any) emerges. Read the original report at BleepingComputer.