How Chosen Brick Malware Threatens Journalists and Activists with Spyware Attacks

Iranian operatives deploy Chosen Brick malware on Windows devices to spy, steal WhatsApp/Telegram data, and wipe systems. Learn how social engineering fuels attacks and how to protect yourself.

How Chosen Brick Malware Threatens Journalists and Activists with Spyware Attacks
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is Chosen Brick malware and who is targeted?

Chosen Brick is sophisticated malware primarily targeting Windows computers. It is designed to spy on high-risk individuals such as dissidents, activists, and journalists seen as threats by a regime. The malware enables attackers to steal sensitive information including files, emails, and chat data from apps like WhatsApp and Telegram, record audio through the microphone, capture screenshots, and even wipe entire systems remotely.

This malware is part of an espionage campaign where attackers carefully research targets before initiating contact via social media. They pose as trusted contacts or technical support to build trust and deliver the malware, exploiting social engineering tactics to bypass normal user caution.

How does the malware operate and communicate?

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents  and journalists - Help Net Security
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists - Help Net Security

Once installed, Chosen Brick enumerates running processes and collects detailed system information to tailor its spying activities. It intercepts web browser data tied to messaging apps like WhatsApp and Telegram, extracting conversation histories and possibly other credentials. The software can download additional malicious payloads to expand control or damage and can delete files or erase the device’s contents altogether.

Command and control occur through Telegram messaging channels, allowing attackers to maintain persistent access and issue instructions stealthily.

What are the risks and implications for users?

The primary risk lies in the invasive surveillance and loss of privacy. Victims of this malware may unknowingly have their conversations, files, and audio recordings exposed to foreign intelligence operatives. In extreme cases, the attackers use the stolen information to conduct physical threats including kidnapping or violence.

The malware’s ability to wipe devices poses additional risk of data loss or disruption for victims reliant on their computing devices for communication or activism.

What defenses can users implement to reduce risk?

NCSC UK on X: "A new advisory exposes Iranian state cyber attackers using  malware dubbed CHOSEN BRICK. Our Director of Operations Paul Chichester  @0xchich says individuals at risk should follow advice in
NCSC UK on X: "A new advisory exposes Iranian state cyber attackers using malware dubbed CHOSEN BRICK. Our Director of Operations Paul Chichester @0xchich says individuals at risk should follow advice in

Vigilance against social engineering is crucial. Users should critically evaluate unsolicited social media contacts and verify identities independently before engaging. Technically, ensuring operating systems and applications have automatic updates enabled reduces exposure to known vulnerabilities.

Antivirus or endpoint protection software should be active and updated to detect or block malicious payloads. Smart screen warnings and phishing-resistant multi-factor authentication (MFA) add extra layers of security by blocking unsafe downloads and making unauthorized access more difficult.

Organizations and individuals handling sensitive communication should enable email scanning and deploy network monitoring to detect suspicious activity early. Regularly searching for indicators of compromise (IoCs) related to this malware can identify infections quickly.

Key takeaway for activists, journalists, and their networks

Chosen Brick represents a severe espionage threat targeting vulnerable populations. Awareness of social engineering tactics combined with rigorous application of technical safeguards is essential to mitigate risks. Given the malware’s destructive and surveillance capabilities, individuals at risk should adopt a layered security approach: maintain software updates, use strong authentication, employ endpoint monitoring, and be cautious with digital trust relationships. These steps do not guarantee immunity but significantly reduce the chances of successful compromise.

React to this story

Related Posts