← Blog · · df00tech

Iranian State Hackers Deploy New CHOSEN BRICK Malware Against Dissidents and Journalists

security-news campaign

Government agencies have issued a warning that Iranian state-linked threat actors are using a previously undocumented Windows malware strain called CHOSEN BRICK in surveillance operations against dissidents, activists, and journalists globally, according to a report from BleepingComputer.

What was reported

Per the advisory, the malware is being used specifically for espionage against individuals rather than broad enterprise targeting — a pattern consistent with prior Iranian state-linked operations against civil society figures. Technical details on the malware's capabilities, delivery mechanism, and specific attribution to a named threat group were not detailed in the available reporting.

Why it matters for defenders

While this campaign targets individuals — dissidents, activists, and journalists — rather than corporations, it's relevant to any organization that supports, employs, or provides services to at-risk populations, including NGOs, media outlets, legal aid groups, and diaspora communities. State-sponsored spyware campaigns against civil society also frequently reuse infrastructure and tradecraft that later surfaces in more conventional intrusions, making early visibility valuable.

What defenders should watch for

  • Monitor for unusual Windows process behavior, persistence mechanisms, and outbound connections on endpoints belonging to high-risk individuals (journalists, activists, NGO staff).
  • Review phishing and social-engineering attempts targeting personal or organizational accounts, a common initial-access vector in Iranian state-linked campaigns.
  • Watch for anomalous scheduled tasks, registry run-key modifications, or unsigned binaries executing from user-writable directories, which are common tradecraft in espionage-focused malware.
  • Organizations supporting at-risk individuals should consider hardening endpoint logging and enabling threat-hunting visibility for this population specifically.

Developing story

Technical indicators of compromise and a detailed malware analysis for CHOSEN BRICK were not available at the time of this writing. This is a developing story based on a government advisory reported by BleepingComputer; we will update our coverage as more technical detail, IOCs, or a formal CVE association (if any) emerges. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.