Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Nation-State Threats

Iranian State-Linked Actors Deploy CHOSEN BRICK Windows Malware Against Global Dissidents

17 September 2026 LetsDefend Infosec 5 min read

Introduction

Recent government advisories have highlighted a new surveillance campaign targeting political dissidents, human‑rights activists, and journalists across multiple continents. The campaign leverages a Windows‑only malware family dubbed CHOSEN BRICK. While public technical details remain scarce, the confirmed involvement of Iranian state‑linked actors raises the stakes for any organization or individual that could be a potential target.

What Happened

Authorities disclosed that a coordinated group tied to the Iranian government has begun distributing CHOSEN BRICK to compromise Windows systems belonging to outspoken critics of Tehran’s policies. The malware’s primary function appears to be covert data collection, enabling operators to monitor communications, capture files, and potentially exfiltrate sensitive material. The campaign is not limited to a single geography; victims have been identified in Europe, the Americas, and the Middle East.

Technical Details

CHOSED BRICK is confirmed to run exclusively on Microsoft Windows platforms. Beyond that, open‑source intelligence has not released a full binary analysis, so the exact persistence mechanisms, command‑and‑control (C2) protocols, or encryption schemes remain undocumented. However, typical Windows‑based espionage tools employ one or more of the following techniques:

  • Registry modifications to achieve persistence after reboot.
  • Scheduled tasks or service creation that grant the malware elevated execution rights.
  • Code injection into legitimate processes to evade behavioral detection.
  • Encrypted outbound traffic that blends with normal web traffic, complicating network‑level inspection.

Given the targeting of high‑profile individuals, it is reasonable to assume the developers have incorporated anti‑analysis features such as debugger checks or sandbox evasion. The absence of a CVE identifier suggests the threat does not rely on a publicly disclosed software flaw but rather on social‑engineering or compromised supply‑chain vectors to gain initial foothold.

Who Is Affected

The advisory explicitly lists three victim categories:

  1. Political dissidents who oppose the Iranian regime.
  2. Human‑rights activists operating in or reporting on Iran‑related issues.
  3. Journalists covering topics sensitive to the Iranian government.

All three groups share a common reliance on Windows‑based workstations for document creation, email, and secure communications. Consequently, any individual or organization providing technical support, hosting services, or communication channels to these actors could inadvertently become a conduit for the malware.

Why It Matters

State‑linked espionage campaigns differ from financially motivated attacks in several key ways. First, the objective is intelligence collection rather than direct monetary gain, meaning the attackers are willing to invest significant resources to maintain long‑term access. Second, the presence of a dedicated surveillance tool indicates a strategic intent to monitor dissenting voices, potentially influencing public discourse and policy.

For enterprises, the risk extends beyond the immediate victims. A compromised activist’s laptop could be used to infiltrate partner networks, exfiltrate proprietary data, or launch lateral moves against unrelated systems. Moreover, the public perception damage of being associated with a state‑sponsored surveillance operation can erode stakeholder trust.

Exploitation/Attack Information

The exploitation status is listed as reported, confirming that CHOSEN BRICK has been observed in active deployments. Government agencies have issued warnings based on forensic evidence collected from compromised machines. While the exact infection chain has not been disclosed, typical entry points for similar tools include:

  • Phishing emails containing malicious attachments or links.
  • Compromised legitimate software updates delivered through a trusted supply chain.
  • Remote desktop protocol (RDP) brute‑force attacks that grant attackers direct system access.

Each vector aligns with the broader pattern of state‑level actors leveraging both technical and human weaknesses to achieve footholds.

Recommended Actions

Organizations supporting at‑risk individuals should adopt a layered defense strategy:

  1. Patch Management – Ensure all Windows endpoints run the latest security updates. Even if CHOSEN BRICK does not exploit a known vulnerability, reducing the attack surface limits opportunistic entry.
  2. Endpoint Detection and Response (EDR) – Deploy solutions capable of behavioral monitoring to flag anomalous process injection, registry changes, or unusual network traffic.
  3. Network Segmentation – Isolate high‑risk workstations from critical infrastructure. Use firewalls to restrict outbound connections to known, reputable destinations.
  4. Multi‑Factor Authentication (MFA) – Enforce MFA on all privileged accounts and remote access services such as RDP and VPN.
  5. User Training – Conduct targeted phishing awareness campaigns for activists, journalists, and their support staff, emphasizing the dangers of unsolicited attachments and links.
  6. Incident Response Planning – Maintain a playbook that includes forensic collection of Windows logs, memory dumps, and network traffic should a compromise be suspected.
  7. Threat Intelligence Feeds – Subscribe to reputable sources that track Iranian state‑linked activity to receive timely indicators of compromise (IOCs) related to CHOSEN BRICK.

Implementing these measures does not guarantee immunity, but it raises the cost of successful intrusion and improves detection speed.

Conclusion

The emergence of CHOSEN BRICK underscores a persistent trend: nation‑state actors continue to develop bespoke malware for the explicit purpose of silencing dissent. While the public technical dossier on the strain is limited, the confirmed involvement of Iranian state‑linked hackers and the targeting of globally dispersed activists and journalists demand immediate attention.

Stakeholders must treat the advisory as a call to reinforce Windows security hygiene, elevate monitoring capabilities, and provide tailored training for high‑risk user groups. Proactive defenses will not only protect individual targets but also safeguard the broader ecosystem from being leveraged as a surveillance platform.

Sources

  • BleepingComputer: https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
#Malware #State-Sponsored Threats #Surveillance #Windows #Activist Targeting
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Exploitation/Attack Information Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Nation-State Threats
10 Sep 2026 4 min read

China‑Aligned Threat Groups Actively Exploit Zero‑Day Chain Across Multiple Sectors

Multiple China‑aligned threat groups have rapidly weaponized a series of undisclosed zero‑day flaws, targeting a broad set of organizations. The campaign is ongoing and expected to expand, underscoring the need for heightened vigilance and rapid mitigation.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 5 min read

Citrix NetScaler ADC & Gateway Critical RCE Vulnerabilities Actively Exploited

Citrix disclosed two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway that are being exploited in the wild. Patches have been released, but one vulnerability affects every deployment, including default configurations.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

CISA Flags Actively Exploited SharePoint Flaw (CVE‑2026‑65660) with Federal Patch Deadline

CISA has added CVE‑2026‑65660 for Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a September 28 patch deadline for federal agencies. Immediate remediation is required.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.