Western cybersecurity authorities and federal intelligence agencies have raised urgent alarms regarding a sophisticated, state-sponsored digital espionage operation attributed to Iranian threat actors. The campaign relies on a previously under-documented Windows malware strain designated as CHOSEN BRICK, which is being actively deployed to compromise the personal and professional computing environments of high-risk civilian populations. Rather than focusing on corporate intellectual property, financial institutions, or critical infrastructure—the typical primary objectives of traditional cyber-espionage—this offensive targets a vulnerable demographic: journalists, political dissidents, human rights activists, and individuals exiled from or openly critical of the Iranian regime.
The coordinated disclosure, issued jointly by cybersecurity defense centers and law enforcement bodies in the United States, the United Kingdom, and the Netherlands, highlights an alarming convergence of cyber operations and physical security threats. According to the advisory, the compromised individuals reside primarily across Western Europe and North America. The malicious tooling engineered by these state-backed operators underscores how modern advanced persistent threat (APT) groups refine their software development lifecycles to build modular, highly targeted surveillance utilities capable of evading routine endpoint detection and response (EDR) agents deployed on standard consumer hardware.
At the core of this technical apparatus is CHOSEN BRICK, a multi-faceted reconnaissance and data-harvesting payload built specifically for the Windows operating system. Once successfully introduced into a target’s machine, the malware grants its handlers deep visibility into the victim’s digital footprint. It is structurally designed to harvest sensitive communication streams, including localized archives from desktop messaging applications like Telegram and WhatsApp, alongside traditional email client databases. Furthermore, the malware possesses built-in capabilities to capture continuous screen telemetry, log keystrokes, and periodically record ambient audio via the host device’s microphone, turning a victim’s personal workstation into a constant listening post.
The delivery mechanisms employed by these threat actors rely heavily on highly customized social engineering tactics rather than zero-day software exploits. Because their intended victims often maintain strict operational security protocols regarding enterprise software, the attackers frequently target personal computing devices where corporate monitoring is absent. The assault vectors typically begin on mainstream messaging platforms such as WhatsApp or Telegram. The operators meticulously build rapport over extended periods or impersonate trusted professional contacts, colleagues, or technical support representatives to lower the victim’s guard.

Once trust is established, the victims are enticed into downloading and executing malicious payloads disguised as legitimate, highly recognizable software utilities. The list of spoofed applications documented by investigative authorities spans a wide variety of productivity, media, and security tools, including popular video and image editing suites like Pictory and RunwayML, widely used archive management and password utilities like KeePass, media players such as Adobe Flash Player, and well-known antivirus products including Norton. In instances where the social engineering pretext demands heightened urgency or personal relevance, the operators have even resorted to medical-themed pretexts, utilizing fraudulent clinical documents—such as simulated MRI scan files—as conversational hooks to induce the target into opening the malicious file without hesitation.
Upon execution, these decoy applications behave deceptively. They frequently launch a fully functional, authentic-looking graphical user interface that matches the user’s expectations, preventing immediate suspicion. Meanwhile, in the background, the application silently unpacks and installs the CHOSEN BRICK payload into the underlying file system. To maintain persistence across reboots, the malware writes specific values into the Windows Registry Run keys, ensuring that the surveillance module reactivates automatically every time the operating system is initialized.
Evasion techniques embedded within CHOSEN BRICK demonstrate a clear understanding of contemporary security software configurations. Upon initial staging, the malware systematically modifies local system parameters to add specific exclusion paths to Microsoft Defender. By carving out these administrative blind spots within the default Windows security apparatus, the utility prevents the operating system’s native antivirus engine from flagging, quarantining, or terminating its processes.
For command-and-control (C2) communication, the operators utilize an innovative, low-infrastructure methodology that blends seamlessly with legitimate network traffic. Rather than relying on traditional, easily blockable external IP addresses or standard web shells, CHOSEN BRICK establishes operational links through custom Telegram bots mapped uniquely to individual victim identifiers. This design choice complicates defensive attribution and network filtering, as communication with Telegram’s application programming interface (API) is widely permitted across almost all residential and corporate internet gateways to prevent breaking routine messaging services.
Once the C2 channel is established and verified, the exfiltration pipeline begins moving harvested intelligence out of the victim’s environment. Stolen documents, credentials, and multimedia files are systematically packaged and funneled through cloud storage and object-hosting platforms, including VultrObjects, StorjShare, and Backblaze B2. In more recent iterations of the malware observed by incident responders, developers have integrated SOCKS5 proxy routing capabilities. This network-layer enhancement tunnels outgoing traffic through distributed proxy services such as IPRoyal and LightningProxies, effectively obscuring the true geographic origin of the extraction routines and confounding traditional forensic analysis.

The implications of this campaign extend far beyond standard digital data theft. Investigators and geopolitical analysts note that the intelligence gathered through CHOSEN BRICK operations frequently feeds into broader harassment campaigns. In multiple instances, stolen private conversations, personal photographs, and sensitive documents have been weaponized and uploaded to pro-regime leak sites or distributed via social media networks to discredit, intimidate, and silence critics living abroad. This digital harassment directly correlates with an elevated physical risk profile for expatriate dissidents, who already navigate hostile operating environments far from their countries of origin.
Government security advisories emphasize that this activity represents an intentional, strategic effort by the Iranian state to project power beyond its physical borders. Intelligence assessments included in the joint warnings point out that cyber espionage in this context serves as a force multiplier for transnational repression. In severe historical precedents, compromised communications and digital tracking have directly preceded physical surveillance, attempted kidnappings, and targeted lethal operations orchestrated by intelligence services against individuals deemed enemies of the state.
Defending against an adversary that utilizes targeted social engineering and customized, low-prevalence malware requires a rigorous, multi-layered defensive posture. Cybersecurity analysts urge potential high-risk individuals—particularly independent journalists, human rights defenders, and political activists—to conduct thorough audits of their personal devices. Recommendations include inspecting Windows Registry Run and RunOnce entries for unauthorized persistence mechanisms, reviewing active background tasks, and scrutinizing network logs for anomalous outbound connections.
Specifically, security teams advise monitoring for unexpected or persistent traffic destined for Telegram’s API endpoints, along with unusual data transfers directed toward cloud-hosting and decentralized storage providers like VultrObjects, StorjShare, and Backblaze B2. Furthermore, unverified connections routing through commercial proxy services such as IPRoyal and LightningProxies should be treated as immediate indicators of compromise (IoCs). By heightening digital hygiene, verifying the integrity of downloaded software through cryptographic hash checking, and minimizing reliance on personal devices for sensitive communications, high-risk targets can substantially mitigate their exposure to sophisticated state-sponsored surveillance operations like those driven by CHOSEN BRICK.
