Full Report
'Enemies of the regime' on notice
Analysis Summary
# Incident Report: Iranian State-Sponsored "Chosen Brick" Malware Campaign
## Executive Summary
Iranian state-sponsored actors are targeting high-value individuals—including dissidents, activists, and journalists—with a custom Windows-based data stealer dubbed "Chosen Brick." The campaign utilizes sophisticated social engineering via messaging apps to deploy malware designed for surveillance and total system compromise. The primary impact involves the exfiltration of sensitive communications, which the regime reportedly uses to facilitate physical threats, kidnappings, or lethal operations against perceived enemies.
## Incident Details
- **Discovery Date:** September 15, 2026 (Public Advisory Date)
- **Incident Date:** Active since at least 2025
- **Affected Organization:** Individuals (Dissidents, Activists, Journalists) and their associated organizations
- **Sector:** Human Rights, Journalism, Government, and Critical Infrastructure
- **Geography:** Global (Specifically targets international "enemies of the regime")
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing since 2025
- **Vector:** Social Engineering via WhatsApp and Telegram.
- **Details:** Attackers conduct extensive reconnaissance on targets to build rapport. They pose as trusted contacts or industry organizations before sending a malicious file disguised as legitimate software (e.g., Pictory, RunwayML, or KeePass).
### Lateral Movement
- **Details:** While automated lateral movement has not been observed in the wild, agencies note it is "technically possible." The malware primarily focuses on deep compromise of the initial host.
### Data Exfiltration/Impact
- **Details:** The malware steals contacts, emails, and social media messages (WhatsApp/Telegram data from browsers). It also captures audio/screen content and tracks physical movements via digital footprints.
### Detection & Response
- **Discovery:** Identified through joint intelligence operations by the FBI (USA), NCSC (UK), and AIVD (Netherlands).
- **Response Actions:** Issuance of a joint Cybersecurity Advisory (CSA); recommendation for organizations to assist staff in auditing personal devices.
## Attack Methodology
- **Initial Access:** Spear-phishing via social messaging apps (WhatsApp/Telegram).
- **Persistence:** Registry Run Key: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. Survives system reboots.
- **Privilege Escalation:** Not explicitly detailed, but achieves sufficient permissions to modify Windows Defender.
- **Defense Evasion:** Adds specific exclusions to Microsoft Defender Antivirus to prevent scanning of malicious components.
- **Credential Access:** Thefts of browser-stored credentials and session data for Telegram and WhatsApp.
- **Discovery:** Enumerates running processes and system information.
- **Lateral Movement:** Manual capability to download additional payloads for network expansion.
- **Collection:** Audio recording, screen captures, and harvesting of email/messaging databases.
- **Exfiltration:** Uses a victim-specific Telegram bot for Command-and-Control (C2) and data transfer.
- **Impact:** Surveillance, data theft, and potential system wiping capabilities.
## Impact Assessment
- **Financial:** Unknown; primary motive is intelligence and suppression.
- **Data Breach:** High; total compromise of private communications and contacts.
- **Operational:** Disruption of activist/journalist activities; risk of system wiping.
- **Reputational:** High risk to organizations whose staff are compromised, potentially exposing internal sources.
- **Physical:** **Critical.** Intelligence gathered is used to plot kidnappings or lethal operations.
## Indicators of Compromise
- **Network Indicators:**
- C2 communications to Telegram API endpoints (e.g., `api.telegram[.]org`) via specific bot tokens.
- **File Indicators:**
- Malicious binaries disguised as: `Pictory`, `RunwayML`, `Norton Antivirus`, `Telegram`, `Adobe Flash Player`, `KeePass`.
- **Behavioral Indicators:**
- Unexpected modifications to Microsoft Defender exclusion lists.
- New entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.
## Response Actions
- **Containment:** Disconnecting infected Windows machines from the internet; terminating malicious Telegram bot connections.
- **Eradication:** Removal of malicious registry keys and files; resetting all credentials used on the device.
- **Recovery:** Restoring systems from clean backups; continuous monitoring of personal accounts for unauthorized access.
## Lessons Learned
- **Blurring of Personal/Professional:** State actors are increasingly targeting personal devices to bypass corporate security perimeters.
- **Reconnaissance Depth:** The high level of "rapport building" indicates that standard anti-phishing training (looking for typos or generic greetings) is insufficient against these actors.
## Recommendations
- **User Education:** Train high-risk staff to never download software via social messaging apps, even from "trusted" contacts.
- **Endpoint Protection:** Enforce policies that prevent users from modifying Microsoft Defender exclusion lists.
- **MFA:** Implement hardware-based Multi-Factor Authentication (MFA) to protect accounts if session tokens are stolen.
- **Personal Device Security:** Provide support/VPNs for staff using personal devices for work-related communications in high-risk geographies.