Back Uk.Pcmag Iranian Hackers Use Fake Norton Antivirus to Spread Windows Spyware
Iran has allegedly been using malicious apps that impersonate cybersecurity products such as Norton Antivirus and the password manager KeePass to secretly infect victims with Windows-based spyware . On Tuesday, the FBI joined the UK to alert the public the threat, which has been traced to Iranian state- hackers attempting to target dissidents, activists, and journalists. The FBI’s advisory notes that Iranian hackers will first try to build a rapport with their targets via social messaging apps, posing as IT customer support. In other cases, they will pretend to be a known . “The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target,” the FBI added. The AI video creation apps Pictory and RunwayML have been used as bait, in addition to Norton Antivirus, KeePass , the messaging app Telegram , and Adobe Flash Player. In other cases, the Iranian hackers also used a fake MRI test result to phish their targets. The malicious bait has been designed to download spyware called “Chosen Brick,” which surprisingly targets desktop PCs, rather than mobile phones. “In all observed instances, the malware has been exclusively targeted at the Windows operating system,” the FBI added. The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says. The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
On Tuesday, the FBI joined the UK to alert the public the threat, which has been traced to Iranian state- hackers attempting to target dissidents, activists, and journalists. The FBI’s advisory notes that Iranian hackers will first try to build a rapport with their targets via social messaging apps, posing as IT customer support. In other cases, they will pretend to be a known . “The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target,” the FBI added. The AI video creation apps Pictory and RunwayML have been used as bait, in addition to Norton Antivirus, KeePass , the messaging app Telegram , and Adobe Flash Player. In other cases, the Iranian hackers also used a fake MRI test result to phish their targets. The malicious bait has been designed to download spyware called “Chosen Brick,” which surprisingly targets desktop PCs, rather than mobile phones. “In all observed instances, the malware has been exclusively targeted at the Windows operating system,” the FBI added. The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says. The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
“The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target,” the FBI added. The AI video creation apps Pictory and RunwayML have been used as bait, in addition to Norton Antivirus, KeePass , the messaging app Telegram , and Adobe Flash Player. In other cases, the Iranian hackers also used a fake MRI test result to phish their targets. The malicious bait has been designed to download spyware called “Chosen Brick,” which surprisingly targets desktop PCs, rather than mobile phones. “In all observed instances, the malware has been exclusively targeted at the Windows operating system,” the FBI added. The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says. The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
The malicious bait has been designed to download spyware called “Chosen Brick,” which surprisingly targets desktop PCs, rather than mobile phones. “In all observed instances, the malware has been exclusively targeted at the Windows operating system,” the FBI added. The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says. The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
The spyware contains several capabilities, including capturing screen content, accessing the microphone to record audio, collecting message data from browsers, and downloading additional malware components, among others. In some instances, the Iranian hackers exploited the screen-capturing function to publish personal details “in order to further harass the victim,” the FBI says. The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
The apparent goal is to suppress individuals who are against the Iranian regime. “The personal details of some victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected,” the UK’s National Cyber Security Centre said . The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
The FBI’s advisory also mentions steps that victims can take to detect the spyware, which bypasses the built-in Windows Defender. The agency was vague how to remove the spyware, but a full factory reset should clear it up. The FBI also urged users to “enable antivirus or anti-malware software on your device and run antivirus software regularly," and to avoid downloading apps from unofficial sources.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
