Back Cyberinsider Iranian malware steals Telegram and WhatsApp data from targets
Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio.
The malware has been used internationally since at least 2025 and relies heavily on social engineering, while also using Telegram infrastructure for command-and-control.
The findings were published in a joint advisory from the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Netherlands’ General Intelligence and Security Service (AIVD). According to their assessment, CHOSEN BRICK has targeted people in several countries, including the UK, US, and Netherlands.
Attacks begin with extensive research into prospective victims, followed by social engineering over messaging services such as WhatsApp and Telegram. Attackers may impersonate someone the target already knows or pose as technical support to build trust before sending a malicious file.
Observed lures have masqueraded as legitimate applications including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. Other attacks delivered files presented as MRI scan results. The malicious files display convincing content matching the pretext while silently installing CHOSEN BRICK in the background. All infections documented in the advisory targeted Windows systems.
Once installed, CHOSEN BRICK typically gains persistence through the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key and can add Microsoft Defender exclusions to reduce the chance of detection. It then communicates with Telegram for command-and-control, with operators assigning a separate Telegram bot ID to each victim.
The malware can enumerate running processes and system information, take screenshots, activate the microphone, steal email, and copy Telegram and WhatsApp browser data. Operators can also download additional malware, delete files, and, in at least one analyzed sample, wipe the compromised computer.
Stolen information can be exfiltrated through Telegram or cloud-storage services including VultrObjects and StorjShare. More recent variants can route traffic through HTTPS or SOCKS5 proxies to help conceal their Telegram communications. The advisory also notes that personal information obtained from some victims later appeared on pro-Iranian leak sites.
People at higher risk should avoid installing software received through messages or unexpected links and instead download applications directly from official sites or app stores. The agencies also recommend keeping Windows and applications updated, maintaining active antivirus protection, and never ignoring or bypassing SmartScreen warnings.
Google patches Pixel modem zero-day exploited in targeted attacks
Steam client flaw with no fix enables privilege elevation on Windows
HBO Max account hijacked in PasteSwitch malware campaign
CenterPoint Energy confirms data breach after hacker claims 7.49M records
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
Nintendo warns of Switch code execution flaw via on-screen QR codes
Amar Ćemanović is an experienced editor and trained engineer with a keen eye for detail and a passion for technology. Based in Bosnia, Amar specializes in producing high-quality, engaging content. He holds a Master’s degree in engineering, which helps him maintain a meticulous approach to all editorial work. Amar brings a well-rounded knowledge base, covering everything from tech solutions to privacy tools.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
