Full Report
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
Analysis Summary
# Tool/Technique: CHOSEN BRICK
## Overview
CHOSEN BRICK is a specialized malware family utilized by Iranian state-sponsored cyber actors primarily for espionage and surveillance. Its purpose is to infiltrate the personal and professional devices of dissidents, activists, and journalists to collect sensitive information, including contacts, emails, and social media communications. This intelligence is frequently used to track movements and support the repression of individuals perceived as threats to the Iranian regime.
## Technical Details
- **Type:** Malware family (Spyware/Infostealer)
- **Platform:** Windows (Cross-platform delivery via personal and corporate devices)
- **Capabilities:** Information theft, surveillance, C2 via legitimate messaging services, and social engineering masquerading.
- **First Seen:** Approximately 2025
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.003 - Phishing: Spearphishing via Service
- **TA0002 - Execution**
- T1204.002 - User Execution: Malicious File
- **TA0007 - Discovery**
- T1589 - Gather Victim Identity Information
- **TA0011 - Command and Control**
- T1102 - Web Service: Bidirectional Communication (Telegram)
- **TA0009 - Collection**
- T1114 - Email Collection
- T1087 - Account Discovery
## Functionality
### Core Capabilities
- **Information Stealing:** Exfiltration of contact lists, emails, and messages from social media platforms.
- **Identity Masking:** Blends in with legitimate system processes to avoid basic detection.
- **Lure Disguise:** Deployed as legitimate-looking applications such as Norton Antivirus, Telegram, KeePass, Adobe Flash Player, or medical records (MRI scans).
### Advanced Features
- **Telegram C2:** Utilizes the Telegram API for Command and Control (C2) traffic, allowing malicious communications to blend in with legitimate network traffic.
- **Cross-Device Transitioning:** Actors specifically target corporate devices first and, if unsuccessful, pivot to personal devices by building rapport through social messaging apps (WhatsApp/Telegram).
## Indicators of Compromise
*Note: Specific hashes and registry keys were not detailed in the provided excerpt; however, based on the report, the following indicators apply:*
- **File Names:** `Pictory`, `RunwayML`, `Norton Antivirus`, `Telegram`, `Adobe Flash Player`, `KeePass`, and files appearing as `MRI scan results`.
- **Network Indicators:**
- `api[.]telegram[.]org` (Abused for C2)
- **Behavioral Indicators:**
- Unusual messaging activity from known contacts on WhatsApp/Telegram asking to download files.
- Unexpected application installation prompts from untrusted sources.
## Associated Threat Actors
- **Iranian State-Sponsored Actors** (Specifically those targeting dissidents and journalists).
## Detection Methods
- **Behavioral Detection:** Monitor for unauthorized processes leveraging the Telegram API (`api[.]telegram[.]org`) for outbound data transfers, especially from non-messaging applications.
- **Signature-based Detection:** Deployment of antivirus signatures for the masqueraded application names (e.g., fake KeePass or Flash installers).
- **Social Engineering Awareness:** Monitoring for "rapport-building" patterns where unknown entities or compromised contacts pivot conversations to file sharing.
## Mitigation Strategies
- **Prevention:** Exercise extreme caution when receiving unsolicited files or links via social messaging apps, even from known contacts.
- **Hardening:**
- Implement strict application whitelisting to prevent the execution of unauthorized "authentic-looking" software.
- Use Multi-Factor Authentication (MFA) on all social media and email accounts.
- Ensure all software (KeePass, Telegram, etc.) is downloaded only from official vendor websites.
- **Training:** Conduct specialized social engineering training for high-risk individuals (journalists, activists) regarding the "long-con" rapport-building techniques used by Iranian actors.
## Related Tools/Techniques
- **Social Engineering:** Use of "trusted entity" personas (Technical support, known colleagues).
- **Data Leaks:** Use of pro-Iranian leak sites to publish stolen victim data.