Subscribe Sign in

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

3 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1×3 C2×5 D2 D3×4 D4 E3×4 F2×3 all 30 rules
  • Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments said.
  • The Iranian spies do an amount of research to prepare for these social engineering campaigns.
  • Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said.
  • Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot.
  • In August, America’s lead cybersecurity agency, CISA, said that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Iranian state cyber actors are targeting people using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments said.

The report’s most important sentence, shortened and in plain words. How

Headline check

All two things this headline claims are in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

Read the full reportHide the full report3 min

Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments said.

In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals’ devices, stealing their contacts, emails, and social media messages, which allows the spies to track people’s movements, the FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) said on Tuesday.

“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”

These attacks typically begin with WhatsApp and Telegram messages, purportedly coming from individuals and organizations that the victim knows and trusts.

The Iranian spies do an amount of research to prepare for these social engineering campaigns. By the time they send the initial message via a social media app, they have “extensive” knowledge of the targeted individual, their contacts, and relevant industry organizations to make the phony messages more believable, according to the agencies.

After building rapport with the mark, the attackers convince them to download and open a file that appears to be an application. Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said.

Upon opening the file, the malware executes without the victim’s knowledge, and will survive a reboot of the target device. Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot.

While the malware hasn’t yet been observed to automate lateral movement across the network, this is “technically possible,” the advisory noted.

It does, however, download additional malware and set up persistence for new payloads on infected devices, using the same registry key that Chosen Brick uses to establish its own persistence on a Windows device: HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

Other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system.

“Organizations that are concerned Chosen Brick has been executed should contact their IT providers, either internal or external, to investigate,” the US, UK, and the Netherlands said. “As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too.”

The Western agencies’ latest Iran alert follows a series of water and energy cyberattacks that researchers and media reports have linked to Iran, although the US and UK governments have stopped short of formally attributing them, as the military conflict between Iran and the US approaches its seventh month.

In August, America’s lead cybersecurity agency, CISA, said that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems. CISA did not, however, attribute the campaign to Iran or anyone else.

Around the same time, a suspected Iran-linked cyberattack also shut down a small UK power plant.

Also in August, five US agencies said that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other facilities.

“This is not a theoretical risk – it is an active threat,” the feds said. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 11 13 77 -0.3 38.2
Mundane Readneutralized from The Register 6.4 10 77 -0.3 38.2

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works