Executive Summary
Iranian state-linked hackers deployed CHOSEN BRICK malware in a sophisticated espionage campaign targeting dissidents, activists, and journalists in the U.S., U.K., and Netherlands throughout 2026. The attack began with social engineering via WhatsApp and Telegram, where threat actors impersonated trusted contacts to deliver malicious files disguised as legitimate applications like Norton Antivirus, Adobe Flash Player, and KeePass. Once installed, CHOSEN BRICK established persistence through Windows Registry modifications, evaded detection by adding Microsoft Defender exclusions, and exfiltrated sensitive data including email communications, Telegram and WhatsApp messages, screenshots, and audio recordings through Telegram bots and cloud storage services.
This campaign exemplifies the growing sophistication of nation-state actors leveraging popular communication platforms and cloud infrastructure for command-and-control operations, highlighting the urgent need for enhanced detection capabilities against encrypted communications channels and cloud-based data exfiltration.
Why This Matters Now
Nation-state actors are increasingly weaponizing legitimate cloud services and encrypted messaging platforms for espionage operations, making traditional perimeter defenses insufficient and requiring immediate investment in zero-trust architectures and advanced threat detection capabilities.
Attack Path Analysis
Iranian state-linked hackers conducted a sophisticated social engineering campaign targeting dissidents, activists, and journalists by impersonating trusted contacts via WhatsApp/Telegram to deliver CHOSEN BRICK malware disguised as legitimate applications. The malware established persistence through Registry Run keys, escalated privileges by adding Microsoft Defender exclusions, maintained command and control through unique Telegram bots and SOCKS5 proxies, and exfiltrated sensitive communications and system data to cloud storage services and pro-Iranian leak sites for harassment and intelligence purposes.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers sent social engineering messages via WhatsApp/Telegram impersonating trusted contacts or technical support, tricking victims into downloading malicious files disguised as legitimate applications (Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass)
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
User Execution: Malicious File
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Impair Defenses: Disable or Modify Tools
Screen Capture
Audio Capture
Exfiltration Over C2 Channel
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
PCI DSS 4.0 – Deploy a Change Detection Mechanism
Control ID: 11.5.1
CISA Zero Trust Maturity Model 2.0 – Network Monitoring
Control ID: DE.CM-1
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Web Filtering
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Newspapers/Journalism
Iranian state hackers specifically target journalists with CHOSEN BRICK malware for espionage, stealing communications and exfiltrating data through encrypted channels.
Civic/Social Organization
Dissidents and activists face targeted surveillance through social engineering attacks, with stolen data published on pro-Iranian sites increasing physical risks.
Government Administration
Government agencies issue joint advisories as Iranian hackers employ sophisticated malware for international surveillance operations against perceived regime threats.
Non-Profit/Volunteering
Human rights organizations vulnerable to state-sponsored espionage campaigns targeting communications through medical lures and legitimate application impersonation techniques.
Sources
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targetshttps://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/Verified
- Iranian cyber targeting of dissidents, activists and journalistshttps://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalistsVerified
- FBI Joint Cybersecurity Advisory on Iranian Threat Actor Targetinghttps://www.fbi.gov/news/press-releasesVerified
- Iran's Cyber Operations Against Dissidents and Civil Societyhttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Iranian state-linked campaign by limiting lateral movement between workloads and reducing the blast radius of CHOSEN BRICK malware through network segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial malware deployment may still succeed through social engineering, but the compromised endpoint would likely be contained within its designated network segment with limited reachability to critical systems
Control: Zero Trust Segmentation
Mitigation: Local privilege escalation may succeed on the compromised host, but elevated privileges would likely be constrained to the segmented network zone without expanding access to adjacent workloads or critical infrastructure
Control: East-West Traffic Security
Mitigation: System enumeration may provide local host information, but attempts to move laterally to other systems would likely be blocked by east-west traffic controls enforcing least-privilege connectivity between workloads
Control: Multicloud Visibility & Control
Mitigation: C2 communications may be established initially, but ongoing command channels would likely be detected and constrained through centralized visibility across cloud environments and anomalous traffic pattern analysis
Control: Egress Security & Policy Enforcement
Mitigation: Data collection from the compromised endpoint may succeed, but large-scale exfiltration to external cloud services would likely be constrained by egress policies restricting unauthorized outbound data transfers
Despite CNSF protections, some sensitive data from the initially compromised endpoint could still be exposed, but the overall impact would likely be reduced in scope compared to unrestricted network access
Impact at a Glance
Affected Business Functions
- Personal Communications Security
- Digital Privacy Protection
- Journalistic Operations
- Activist Coordination
Estimated downtime: N/A
Estimated loss: N/A
Email communications, Telegram and WhatsApp messages, audio recordings from device microphones, screenshots of user activities, and system information from targeted dissidents, activists, and journalists. Stolen data subsequently published on pro-Iranian leak sites for harassment purposes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement and limit malware propagation through identity-based policies and microsegmentation
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration to cloud storage services and detect suspicious outbound connections to Telegram API
- • Enable Multicloud Visibility & Control to detect anomalous interactions with external services and suspicious automation patterns in communication applications
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on covert tools like remote access applications
- • Deploy Encrypted Traffic (HPE) controls to secure data in transit and prevent packet sniffing during exfiltration activities



