Back Bankinfosecurity Iranian Hackers Dodging Corporate Defenses to Reach Critics
Iranian state hackers are targeting dissidents, activists and journalists over messaging apps and pushing them to open malicious files on their personal devices to avoid corporate security controls.
See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime
The U.K. National Cyber Security Centre, the FBI and the Netherlands' General Intelligence and Security Service published a joint advisory on a Windows spyware family the British agency tracks as Chosen Brick, which adds exclusions to Microsoft's antivirus tools to evade detection. The advisory comes as the United States has resumed strikes on Iranian targets in recent days (see: Iran Cyber Risk Climbs as US Resumes Strikes ).
Iranian threat actors typically make first through a target's work device. If that delivery fails or the risk of detection appears too high, the attacker asks the target to open the file on a personal machine instead, according to the advisory.
The agencies urged organizations to the advisory with employees likely to be targeted and to help staff check their personal devices for potential exploit.
Chosen Brick has been used since at least 2025 against individuals in the U.K., the U.S. and the Netherlands, among other countries. It can pull a target's contacts, emails and social media messages, capture screen content and switch on a device's microphone.
The agencies warned that access could even allow Iranian operators to track a victim's movements.
The advisory says Iran "almost certainly" uses cyber operations to support the repression of perceived regime opponents, and that its intelligence services have in some cases plotted kidnappings or lethal operations against targeted individuals abroad. Personal details from some earlier Chosen Brick victims have surfaced on pro-Iranian leak sites.
Operators research targets extensively before reaching out over messaging platforms such as WhatsApp and Telegram, according to the advisory, often posing as someone the target already knows or as the platform's own technical support. Examples have included fake installers for Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, as well as files disguised as MRI scan results (see: Iranian Hackers Using Fake Job Sites to Breach Defense Firms ).
Each targeted malware attack displays a convincing screen that matches its theme while it downloads and runs the core spyware in the background. Once installed, the malware survives reboots by writing itself to a Windows registry run key and adds exclusions to Microsoft Defender to avoid detection.
Each infected machine reports to its own Telegram bot, which the agencies described as a precaution against cross-contamination between victims.
The agencies have not observed Chosen Brick moving laterally on its own, but said it can fetch and install additional malware, and at least one sample carried functionality to wipe a system. Operators have staged follow-on payloads in a directory that the advisory says was created specifically to deploy malware.
Defenders are advised to investigate unexpected connections to legitimate services the malware abuses, including Telegram's API, Backblaze B2, Vultr Object Storage, Storj, IPRoyal and Lightning Proxies. The advisory also recommends checking registry run keys for unfamiliar entries, noting that file and value names may change.
The FBI in March warned that cyber actors with Iran's Ministry of Intelligence and Security were using Telegram as command-and-control infrastructure for malware aimed at dissidents and journalists opposed to the regime. The bureau released further technical analysis of Chosen Brick alongside the alert, according to the NCSC (see: Cyberattacks and Unpredictable Targeting Remain an Iran Risk ).
For managed devices, the agencies recommended phishing-resistant multifactor authentication, application allowlisting and endpoint monitoring. People who manage their own machines should also download software only from official sources and never override SmartScreen warnings on downloaded files, the advisory says.
Cyberwarfare / Nation-State Attacks
Fraud Management & Cybercrime
Managing Editor, GovInfoSecurity
Riotta is a journalist based in Washington, D.C. He earned his master's degree from the Columbia University Graduate School of Journalism, where he served as 2021 class president. His reporting has appeared in NBC News, Nextgov/FCW, Newsweek Magazine, The Independent and more.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
