$ techbeacon▋
Malware

Iran-Linked Hackers Deploy New "Chosen Brick" Malware to Target Critics and Reporters

Iran-Linked Hackers Deploy New "Chosen Brick" Malware to Target Critics and Reporters

U.S. and European security agencies have raised alerts about a fresh Windows‑based malware strain, dubbed "Chosen Brick," that appears to be operated by hackers with ties to Iran's state apparatus. The campaign is aimed at individuals and organizations that voice opposition to Tehran, including political dissidents, human‑rights activists and journalists covering sensitive topics.

Technical analysis shows that Chosen Brick is delivered through spear‑phishing emails that contain malicious attachments or links to compromised websites. Once executed, the payload establishes a covert channel to command‑and‑control servers, allowing operators to exfiltrate files, record screen activity and capture login credentials. The code is obfuscated to evade detection by conventional antivirus solutions, and it leverages legitimate Windows utilities to blend in with normal system processes.

Officials from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the European Union Agency for Cybersecurity (ENISA) issued joint advisories urging at‑risk groups to scrutinize unsolicited messages and to apply the latest security patches. Both agencies highlighted that the malware has been observed in at least three continents over the past month, suggesting a coordinated, transnational effort.

The focus on activists, dissidents and journalists aligns with a broader pattern of Iranian cyber‑espionage aimed at silencing dissent and gathering intelligence on opposition movements abroad. Past operations have employed tools such as the MuddyWater and Helix Kit families, which similarly targeted political opponents and foreign policymakers. Chosen Brick appears to be a continuation of that strategy, refined to exploit newer Windows features and to avoid detection by updated security products.

Analysts note that the timing of the campaign coincides with heightened diplomatic tensions between Iran and several Western nations, raising concerns that the cyber offensive could be used to influence public discourse ahead of upcoming elections and international negotiations. By compromising the communications of journalists and NGOs, the attackers could potentially shape narratives or pre‑emptively identify sources before they go public.

Security experts recommend a layered defense: employing multi‑factor authentication, restricting administrative privileges, and conducting regular threat‑hunting exercises to locate anomalous network traffic. Organizations that suspect infection are advised to isolate affected machines, preserve forensic evidence and work with national computer‑incident response teams. As the investigation continues, authorities say they will monitor the malware’s evolution and share indicators of compromise with the broader cybersecurity community.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related