bleeping-computer · Crawled Sep 16, 2026

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

5 IoCs
Read original article ↗

AI Summary

Iranian state-linked hackers are deploying a Windows malware named CHOSEN BRICK to conduct cyber espionage against dissidents, activists, and journalists globally. The malware is distributed via social engineering lures on messaging platforms like WhatsApp and Telegram, using disguised malicious files that mimic legitimate applications. Once installed, CHOSEN BRICK collects system information, steals communications from email and messaging apps, captures screenshots, records audio, and can download additional payloads or wipe the system. Data is exfiltrated through Telegram or cloud services, with newer variants using SOCKS5 proxies for stealth.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain VultrObjects Details →
Domain StorjShare Details →
Domain Backblaze B2 Details →
Domain IPRoyal Details →
Domain LightningProxies Details →