Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

CHOSEN BRICK Malware Targeting Windows Systems

Source context: this article examines information published by the source on September 15, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

Threat activity

Iranian state actors are deploying a malware family known as “CHOSEN BRICK” exclusively targeting Windows operating systems. The campaign utilizes sophisticated spear-phishing and social engineering conducted through messaging applications, specifically WhatsApp and Telegram. Attackers build rapport with targets using tailored lures—such as fake MRI results—to trick them into downloading the software.

Once executed, CHOSEN BRICK establishes persistence on the device, allowing it to survive system reboots. The malware is designed for comprehensive data exfiltration, including the collection of emails, contacts, and social media messages. Additionally, it possesses capabilities to capture screen content and access the device’s microphone.

Who may be at risk

The primary targets are individuals perceived as threats to the Iranian regime, specifically dissidents, activists, and journalists globally. Organizations supporting these individuals or managing infrastructure for high-risk personnel are also at risk of exposure if their users’ Windows devices are compromised via these social engineering vectors.

Potential breach-prevention strategy

The reported entry path is spear-phishing via third-party messaging apps (WhatsApp, Telegram) where rapport-building leads to the installation of malicious software. It remains unknown exactly which file types or delivery mechanisms (e.g., direct links or attachments) are used to trigger the initial execution.

Our analysis suggests a similar breach could have been mitigated through the following prioritized actions:

  1. Hardening User-to-Application Interaction: To address the risk of users downloading untrusted software from messaging apps, security leaders should implement application allowlisting or strict execution policies on high-risk Windows endpoints.

    • Responsible Role: Endpoint Security Administrator.
    • Verification: Attempt to execute an unauthorized binary from a downloaded folder to ensure it is blocked by policy.
    • Goal: Prevent initial access.
  2. Targeted Social Engineering Training: To address the use of tailored lures (e.g., fake medical results), high-risk users should receive training on identifying rapport-building tactics used in state-sponsored phishing.

    • Responsible Role: Security Awareness Lead.
    • Verification: Conduct a controlled social engineering simulation mimicking messaging app delivery vectors.
    • Goal: Prevent initial access.
  3. Privilege Restriction: To limit the ability of malware to establish persistence and survive reboots, users should operate with non-administrative privileges by default.

    • Responsible Role: Systems Administrator.
    • Verification: Audit user account permissions to ensure administrative rights are removed from standard profiles.
    • Goal: Limit damage/persistence.
  4. Endpoint Detection for Unauthorized Hardware Access: To address the risk of microphone and screen capture, organizations should deploy monitoring for unauthorized API calls to these peripherals.

    • Responsible Role: SOC Analyst / EDR Engineer.
    • Verification: Review EDR logs for alerts triggered by unusual process access to the microphone or screen-scraping functions.
    • Goal: Improve detection.

Defensive priorities

Defenders should prioritize the identification of Windows assets used by high-risk personnel and ensure these devices are subject to enhanced monitoring. Because CHOSEN BRICK is persistent, a simple reboot is insufficient for remediation. Priority must be placed on implementing the technical analysis provided by the FBI, NCSC, and AIVD to identify indicators of compromise (IoCs) on endpoints.

Detection and validation

Verification of mitigation cannot be achieved through version checks alone, as the threat relies on social engineering rather than a specific software vulnerability. Validation requires:
* IoC Scanning: Utilizing the technical analysis from the FBI/NCSC to scan for known CHOSEN BRICK signatures or persistence mechanisms.
* Behavioral Analysis: Monitoring for unauthorized outbound traffic to known Iranian state-actor infrastructure and unexpected microphone/screen access.

Residual risk remains high for users who continue to use messaging apps on corporate Windows devices, as social engineering can bypass many traditional perimeter defenses.

What remains unknown

The specific technical indicators (hashes, C2 domains) are contained in the external FBI/NCSC advisory and are not detailed in the general announcement. The exact method of persistence used by CHOSEN BRICK to survive reboots is not specified.

Source and editorial note

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists · Source date: September 15, 2026 · Retrieved September 15, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment