Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed
Technology

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

The Register ·
Iranian spies hit Windows machines with Chosen Brick data-stealing malware

Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned.

In all observed cases, Chosen Brick has infected Windows systems exclusively.

Iran has used it since at least 2025 to take over individuals’ devices, stealing their contacts, emails, and social media messages, which allows the spies to track people’s movements, the FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) said on Tuesday.

“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said.

“In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.” These attacks typically begin with WhatsApp and Telegram messages, purportedly coming from individuals and organizations that the victim knows and trusts.

The Iranian spies do a significant amount of research to prepare for these social engineering campaigns.

By the time they send the initial message via a social media app, they have “extensive” knowledge of the targeted individual, their contacts, and relevant industry organizations to make the phony messages more believable, according to the agencies.

After building rapport with the mark, the attackers convince them to download and open a file that appears to be a legitimate application.

Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said.

Upon opening the file, the malware executes without the victim’s knowledge, and will survive a reboot of the target device.

Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot.

While the malware hasn’t yet been observed to automate lateral movement across the network, this is “technically possible,” the advisory noted.

It does, however, download additional malware and set up persistence for new payloads on infected devices, using the same registry key that Chosen Brick uses to establish its own persistence on a Windows device: HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

Other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›