Back Theregister Iranian spies hit Windows machines with Chosen Brick data-stealing malware
CenterPoint Energy confirms intruder helped themselves to customer information 3 hours ago
CenterPoint Energy confirms intruder helped themselves to customer information
September's Windows 11 patch needs an emergency patch of its own 4 hours ago
September's Windows 11 patch needs an emergency patch of its own
Microsoft account refuseniks have another way of installing Windows 5 hours ago
Microsoft account refuseniks have another way of installing Windows
Microsoft drafts feel-good AI model guidelines and wants your input 17 hours ago
Microsoft drafts feel-good AI model guidelines and wants your input
HBO Max account compromised to serve ClickFix attacks 19 hours ago
HBO Max account compromised to serve ClickFix attacks
Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned.
In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals’ devices, stealing their contacts, emails, and social media messages, which allows the spies to track people’s movements, the FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) said on Tuesday.
“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”
These attacks typically begin with WhatsApp and Telegram messages, purportedly coming from individuals and organizations that the victim knows and trusts.
The Iranian spies do a significant amount of research to prepare for these social engineering campaigns . By the time they send the initial message via a social media app, they have “extensive” knowledge of the targeted individual, their contacts, and relevant industry organizations to make the phony messages more believable, according to the agencies.
After building rapport with the mark, the attackers convince them to download and open a file that appears to be a legitimate application. Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said.
Upon opening the file, the malware executes without the victim’s knowledge, and will survive a reboot of the target device. Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot.
While the malware hasn’t yet been observed to automate lateral movement across the network, this is “technically possible,” the advisory noted.
It does, however, download additional malware and set up persistence for new payloads on infected devices, using the same registry key that Chosen Brick uses to establish its own persistence on a Windows device: HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
Other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system.
“Organizations that are concerned Chosen Brick has been executed should their IT providers, either internal or external, to investigate,” the US, UK, and the Netherlands warned. “As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too.”
The Western agencies’ latest Iran alert follows a series of water and energy cyberattacks that researchers and media reports have linked to Iran, although the US and UK governments have stopped short of formally attributing them, as the military conflict between Iran and the US approaches its seventh month.
In August, America’s lead cybersecurity agency, CISA, disclosed that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems . CISA did not, however, attribute the campaign to Iran or anyone else.
Around the same time, a suspected Iran-linked cyberattack also shut down a small UK power plant .
Also in August, five US agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities.
“This is not a theoretical risk – it is an active threat,” the feds warned . ®
Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
Higher-enriched uranium for datacenters has DoE all aglow
HALEU is still being produced at a snail's pace; Nusano says its federal backing could speed things up – eventually
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
America is building datacenters faster than the grid can power them
Meeting expected energy consumption through 2030 will require $110 billion in new generation resources
Open weights are not open source: Why AI's favorite label is under dispute
Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter
Cisco email security boxes can be rooted by... an email
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements
Smartphone makers don't bother to comply with EU repairability requirements
NETWORKS Virgin Media offloads email services to third-party provider
Virgin Media offloads email services to third-party provider
offbeat Retired man turns spare room into Soviet-era supercomputer
Retired man turns spare room into Soviet-era supercomputer
databases Oracle celebrates banner quarter with another round of layoffs
Oracle celebrates banner quarter with another round of layoffs
CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
software Another Microsoft team admits it’s struggling to handle flood of AI-generated code
Another Microsoft team admits it’s struggling to handle flood of AI-generated code
AI AND ML Anthropic and OpenAI look to Uncle Sam to make them too big to fail American model devs are trying to convince Washington to cement their dominance
Anthropic and OpenAI look to Uncle Sam to make them too big to fail
American model devs are trying to convince Washington to cement their dominance
on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing
Datacenter developers want your backyard. FAS says negotiate harder
Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing
LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required
Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late
Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required
SECURITY Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent War is peace. Freedom is slavery. Privacy is surveillance
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
War is peace. Freedom is slavery. Privacy is surveillance
SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers
d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designs
AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
