Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: High
Victim: Dissidents, journalists, and activists
Incident: Deployment of Chosen Brick malware for state-sponsored surveillance and tracking.
Impact: Compromise of personal communications and heightened risk of physical threats or kidnapping.
Attacker: Iranian Intelligence Services
Analysis: The campaign leverages sophisticated social engineering via messaging apps like Telegram and WhatsApp to build trust before delivering the payload. Chosen Brick focuses on harvesting personal contacts, emails, and social media data to monitor movements. The integration of stolen data on pro-Iranian leak sites indicates a dual-purpose strategy of intelligence gathering and active harassment.
Recommendations: Exercise extreme caution with unsolicited messages from unknown contacts on WhatsApp and Telegram.; Implement strict security controls on both corporate and personal devices for high-risk individuals.; Utilize encrypted communication channels and regularly review app permissions for messaging platforms.
Source: SecurityAffairs
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source