Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

CHOSEN BRICK Malware: Windows Persistence and Exposure Analysis

Source context: this article examines information published by the source on September 15, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

Threat activity

CHOSEN BRICK is a malware family attributed to Iranian state cyber actors, observed targeting individuals including dissidents, activists, and journalists since at least 2025. The threat focuses exclusively on the Windows operating system.

The attack chain begins with social engineering via messaging platforms such as WhatsApp and Telegram. Actors build rapport by impersonating trusted entities or technical support to convince targets to download malicious files disguised as legitimate software (e.g., Norton Antivirus, KeePass, Adobe Flash Player) or documents (e.g., MRI scan results).

Once executed, the malware establishes persistence via the registry and connects to unique Telegram Bot IDs for command-and-control (C2). Capabilities include capturing screen content, enabling microphones, stealing email and browser data (specifically WhatsApp and Telegram), and enumerating system information. The actors may also use HTTPS/SOCKS5 proxies to obscure C2 traffic and exfiltrate data via cloud object stores including VultrObjects and StorjShare.

Who may be at risk

Windows users are the primary targets. While the actor often initiates contact through corporate devices, they frequently attempt to transition the target to personal devices to evade corporate security controls if initial attempts fail or detection risks increase.

Potential breach-prevention strategy

Reported entry paths involve social engineering via messaging apps leading to the execution of a malicious file. It remains unknown exactly how the actors conduct their initial research on targets prior to contact.

Our conditional analysis suggests that a similar compromise could have been reduced in likelihood through the following prioritized actions:

  1. Implement Application Allowlisting: To address the execution of unauthorized binaries disguised as legitimate software, infrastructure owners should restrict execution to approved applications.

    • Responsible Role: Endpoint Security Administrator.
    • Verification: Attempt to execute a non-approved binary in a test environment to confirm it is blocked.
    • Goal: Prevent initial access/execution.
  2. Deploy Phishing-Resistant MFA: To mitigate the risk of credential theft or account takeover that may facilitate social engineering, phishing-resistant multi-factor authentication should be enforced.

    • Responsible Role: Identity and Access Management (IAM) Lead.
    • Verification: Audit MFA enrollment logs to ensure hardware-backed keys are in use for high-risk users.
    • Goal: Prevent initial access.
  3. Restrict Non-Standard Directory Execution: To limit the impact of additional malware payloads, defenders could restrict execution from non-standard paths such as C:\Windows \SysWOW64 (noting the intentional space).

    • Responsible Role: System Administrator/Security Engineer.
    • Verification: Use a security tool to monitor for any process attempting to launch from that specific directory.
    • Goal: Limit damage and persistence of secondary payloads.
  4. Enforce Managed Antivirus Configurations: To counter the malware’s ability to add exclusions to Microsoft Defender, administrators should lock down antivirus settings via Group Policy or MDM to prevent unauthorized modifications.

    • Responsible Role: Endpoint Security Administrator.
    • Verification: Attempt to manually add an exclusion as a standard user to verify the action is denied.
    • Goal: Improve detection and limit evasion.

Defensive priorities

Defenders should prioritize reducing the attack surface of endpoints by ensuring all software is kept up-to-date through automatic updates and maintaining active, updated antivirus software. Because this threat targets both corporate and personal devices, security leaders should provide guidance to high-risk staff regarding the dangers of installing software sent via messaging apps.

Detection and validation

Verification of a clean state cannot be achieved by checking registry keys alone, as filenames and directories may change. However, the following indicators support the identification of an existing infection:

  • Registry Persistence: Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for suspicious entries. Previously observed values include SMQDService (pointing to C:\ProgramData\SMQDServicePackages\...\smdqservice.exe) and winappx (pointing to C:\Users\All Users\MicrosoftDistribution\sysmain\winappx.exe).
  • Network Indicators: Review DNS and web proxy logs for unexpected connections to the following domains:
    • api[.]telegram[.]org
    • backblazeb2[.]com
    • vultrobjects[.]com
    • storjshare[.]io
    • iproyal[.]com
    • lightningproxies[.]net
  • File System: Inspect the non-standard directory C:\Windows \SysWOW64 for unauthorized binaries.

Residual risk remains high if these indicators are absent, as the actor may modify their infrastructure or persistence mechanisms to avoid detection.

What remains unknown

It is not known if CHOSEN BRICK possesses automated lateral movement capabilities; while technically possible via its ability to download additional malware, such behavior has not been observed. The full extent of the actor’s target research process and the complete list of all potential C2 domains also remain unknown.

Source and editorial note

Iranian cyber targeting of dissidents, activists and journalists · Source date: September 15, 2026 · Retrieved September 15, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment