Full Report
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Analysis Summary
# Threat Actor: Iranian State Actors
## Attribution & Identity
* **Identification:** Iranian state-sponsored cyber actors.
* **Aliases/Associations:** Referred to as "Iranian state cyber attackers." The advisory was issued jointly by the UK NCSC, US FBI, and the Netherlands AIVD.
* **Affiliation:** Linked to the Iranian regime, specifically used for transnational repression and digital surveillance.
## Activity Summary
Iranian state actors are conducting spear-phishing and spyware campaigns aimed at surveilling and intimidating individuals perceived as threats to the regime. These operations involve building rapport with victims via messaging apps before deploying the **CHOSEN BRICK** malware family. Recent activity includes stealing sensitive messaging history and leaking victim data on pro-Iranian leak sites to increase pressure on targets.
## Tactics, Techniques & Procedures
* **Spear-phishing & Social Engineering:** Tailoring lures to specific interests of the target.
* **Impersonation:** Posing as known contacts or trusted entities on messaging platforms.
* **Platform-specific lures:** Sending malicious files (e.g., fake MRI test results) via WhatsApp and Telegram.
* **Persistence:** The malware is designed to be persistent and survive system reboots on Windows devices.
* **Data Exfiltration:** Collecting contacts, emails, and social media messaging history.
* **Surveillance:**
* Capturing screen content (Screen Capture).
* Accessing device microphones for audio eavesdropping.
* Tracking physical movements/location.
* **MITRE ATT&CK Mapping (Derived from context):**
* T1566 (Phishing)
* T1547 (Boot or Logon Autostart Execution)
* T1113 (Screen Capture)
* T1123 (Audio Capture)
* T1589 (Gather Victim Identity Information)
## Targeting
* **Sectors:** Civil Society, Journalism, Human Rights.
* **Geography:** Global targeting, with specific mentions of the UK, USA, and the Netherlands.
* **Victims:** Dissidents, activists, and journalists perceived to pose a threat to the Iranian regime.
## Tools & Infrastructure
* **Malware:** **CHOSEN BRICK** (a spyware family exclusively targeting Windows operating systems).
* **Infrastructure:**
* **Messaging Apps:** WhatsApp and Telegram used for initial delivery and rapport building.
* **Leak Sites:** Pro-Iranian websites used to publish stolen data.
* **C2:** (Specific IPs/Domains not listed in this summary text, but referenced in the linked FBI technical report: hxxps[:]//www[.]ic3[.]gov/CSA/2026/260915[.]pdf)
## Implications
These campaigns demonstrate Iran’s commitment to "transnational repression"—using cyber tools to reach beyond its borders to silence critics. The use of highly personalized social engineering suggests a high level of reconnaissance. The publication of stolen data on leak sites poses a direct physical safety risk to the victims and their associates.
## Mitigations
* **Social Engineering Awareness:** Familiarize at-risk individuals with the rapport-building techniques used on WhatsApp and Telegram.
* **Device Security:** Utilize the NCSC’s dedicated support for high-risk individuals and sign up for free cyber defense services.
* **Verification:** Exercise caution when receiving unexpected files or links, even from known contacts, especially if the topic is highly specific (like medical results).
* **Technical Defense:** Implement robust endpoint protection to detect the persistence mechanisms of CHOSEN BRICK on Windows systems.
* **Reporting:** Victims in the UK are encouraged to follow government guidance on transnational repression and report incidents to specialist police units.