Executive Summary

Iranian state-linked hackers deployed CHOSEN BRICK malware in a sophisticated espionage campaign targeting dissidents, activists, and journalists in the U.S., U.K., and Netherlands throughout 2026. The attack began with social engineering via WhatsApp and Telegram, where threat actors impersonated trusted contacts to deliver malicious files disguised as legitimate applications like Norton Antivirus, Adobe Flash Player, and KeePass. Once installed, CHOSEN BRICK established persistence through Windows Registry modifications, evaded detection by adding Microsoft Defender exclusions, and exfiltrated sensitive data including email communications, Telegram and WhatsApp messages, screenshots, and audio recordings through Telegram bots and cloud storage services.

This campaign exemplifies the growing sophistication of nation-state actors leveraging popular communication platforms and cloud infrastructure for command-and-control operations, highlighting the urgent need for enhanced detection capabilities against encrypted communications channels and cloud-based data exfiltration.

Why This Matters Now

Nation-state actors are increasingly weaponizing legitimate cloud services and encrypted messaging platforms for espionage operations, making traditional perimeter defenses insufficient and requiring immediate investment in zero-trust architectures and advanced threat detection capabilities.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CHOSEN BRICK adds Microsoft Defender exclusions during installation and uses legitimate cloud services like Telegram, VultrObjects, and StorjShare for command-and-control and data exfiltration to blend with normal traffic.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this Iranian state-linked campaign by limiting lateral movement between workloads and reducing the blast radius of CHOSEN BRICK malware through network segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial malware deployment may still succeed through social engineering, but the compromised endpoint would likely be contained within its designated network segment with limited reachability to critical systems

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Local privilege escalation may succeed on the compromised host, but elevated privileges would likely be constrained to the segmented network zone without expanding access to adjacent workloads or critical infrastructure

Lateral Movement

Control: East-West Traffic Security

Mitigation: System enumeration may provide local host information, but attempts to move laterally to other systems would likely be blocked by east-west traffic controls enforcing least-privilege connectivity between workloads

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communications may be established initially, but ongoing command channels would likely be detected and constrained through centralized visibility across cloud environments and anomalous traffic pattern analysis

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data collection from the compromised endpoint may succeed, but large-scale exfiltration to external cloud services would likely be constrained by egress policies restricting unauthorized outbound data transfers

Impact (Mitigations)

Despite CNSF protections, some sensitive data from the initially compromised endpoint could still be exposed, but the overall impact would likely be reduced in scope compared to unrestricted network access

Impact at a Glance

Affected Business Functions

  • Personal Communications Security
  • Digital Privacy Protection
  • Journalistic Operations
  • Activist Coordination
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Email communications, Telegram and WhatsApp messages, audio recordings from device microphones, screenshots of user activities, and system information from targeted dissidents, activists, and journalists. Stolen data subsequently published on pro-Iranian leak sites for harassment purposes.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement and limit malware propagation through identity-based policies and microsegmentation
  • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration to cloud storage services and detect suspicious outbound connections to Telegram API
  • Enable Multicloud Visibility & Control to detect anomalous interactions with external services and suspicious automation patterns in communication applications
  • Implement Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on covert tools like remote access applications
  • Deploy Encrypted Traffic (HPE) controls to secure data in transit and prevent packet sniffing during exfiltration activities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image