Iran snoops on enemies of the state with Chosen Brick malware controlled using messaging apps | TechRadar

September 16, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: techradar.com

Threat Risk: High
Victim: Journalists, dissidents, and political activists
Incident: Deployment of Chosen Brick malware for state-sponsored espionage and repression.
Impact: Full system compromise, theft of private communications, and potential physical risk to targets.
Attacker: Iranian Intelligence Services
Analysis: The Chosen Brick campaign leverages targeted social engineering on social media to deliver malware to high-value individuals. Once infected, the malware provides comprehensive surveillance capabilities, including audio recording and credential theft from messaging apps. The use of Telegram for command-and-control allows attackers to blend in with legitimate traffic to avoid detection.
Recommendations: Enable phishing-resistant multi-factor authentication (MFA) across all critical accounts.; Implement robust endpoint detection and response (EDR) to monitor for unauthorized system wipes or data exfiltration.; Educate high-risk personnel on sophisticated social engineering tactics involving the impersonation of technical support.
Source: TechRadar

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *