CYBERSECURITY

Iranian Hackers Deploy CHOSEN BRICK Malware Against Global Targets

Iranian Hackers Deploy CHOSEN BRICK Malware Against Global Targets

How Does CHOSEN BRICK Evade Detection?

Government agencies have issued warnings about Iranian state-linked hackers using a Windows malware strain called CHOSEN BRICK to conduct espionage operations targeting dissidents, activists, and journalists across multiple countries. The alert, released in mid-September 2026, highlights the malware’s role in a sustained cyber campaign aimed at gathering sensitive information from individuals critical of the Iranian government. Security researchers note that the tool has been active in recent months, with infections reported in Europe, North America, and the Middle East.

The CHOSEN BRICK malware is designed to infiltrate Windows systems through phishing emails or compromised websites, allowing attackers to steal files, capture screenshots, log keystrokes, and exfiltrate data to remote servers controlled by the hacking group. Once installed, it operates stealthily, evading detection by standard antivirus tools while maintaining persistent access to infected machines. Analysis shows the malware includes modular components that can be updated remotely, enabling hackers to adapt their tactics based on the target’s behavior or location. Experts say the campaign reflects a broader strategy by Iranian intelligence services to silence opposition voices abroad using cyber tools.

What Are the Risks for Journalists and Activists?

The malware uses encryption and obfuscation techniques to hide its code and communication channels, making it difficult for security software to identify malicious activity. It often mimics legitimate Windows processes and encrypts stolen data before transmission, blending in with normal network traffic. Researchers also note that the attackers frequently change command-and-control server addresses to avoid blacklisting. These tactics allow the malware to remain undetected for extended periods, increasing the volume of data that can be harvested from victims.

Individuals targeted by this malware face serious risks, including exposure of private communications, identification of sources, and potential real-world harm if sensitive information is leaked or used for intimidation. The theft of personal data could lead to doxxing, arrest, or violence, particularly in regions where dissent is met with severe repression. Human rights organizations have urged tech companies and governments to improve threat sharing and provide protective tools to vulnerable users. They also call for greater transparency about state-sponsored cyber operations targeting civilians.

Who is behind the CHOSEN BRICK malware campaign? Security agencies attribute the campaign to hacking groups linked to the Iranian government, particularly those involved in intelligence gathering and repression of dissent.

Frequently Asked Questions

Can antivirus software detect CHOSEN BRICK? While some advanced endpoint protection tools may flag variants, the malware’s use of obfuscation and frequent updates makes consistent detection challenging without specialized threat intelligence.

What should potential targets do to protect themselves? Experts recommend avoiding suspicious links, using multi-factor authentication, keeping systems updated, and employing security tools that monitor for unusual behavior rather than relying solely on signature-based detection.

Content written by Bill Toulas for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment