The UK National Cyber Security Centre, working with the US FBI and the Netherlands’ AIVD, published a joint advisory on September 15 detailing spyware dubbed CHOSEN BRICK that Iranian state linked actors have used against dissidents, activists, and journalists worldwide, including targets inside the UK. According to the advisory, the Windows only malware collects contacts, emails, and social media messages, and can capture screen content and access a device’s microphone, giving operators a persistent surveillance channel rather than a one time data grab. NCSC Director of Operations Paul Chichester said, “We will continue to call out malicious cyber activity by the Iranian state and support communities with practical advice to strengthen their online personal security.”

The attack chain matters as much as the payload for the security leader assessing exposure. Operators impersonate contacts on WhatsApp and Telegram, build rapport with a target over time, and tailor lures to individual interests before delivering CHOSEN BRICK, a patient, human driven social engineering process that most email focused phishing defenses never see. The advisory also notes that personal details from earlier victims have already surfaced on pro-Iranian leak sites, turning a surveillance operation into a physical safety risk for the people targeted.

The original insight for enterprise defenders is who this campaign actually implicates. Journalists and activists are rarely inside a corporate security perimeter, but newsrooms, NGOs, and law firms that employ or work with them are, and CHOSEN BRICK’s contact impersonation technique travels well into any environment where staff message external sources on personal chat apps. A SOC that only monitors managed endpoints and corporate email has no visibility into this attack surface at all, the same blind spot CyberTech flagged when a separate Chinese state linked operation chained a patched browser bug into a persistent backdoor. CHOSEN BRICK also fits a longer pattern of Iranian state activity CyberTech has tracked, including the US indictment of Iran’s Mabna Institute hackers, where legal action alone has done little to slow the same actors from targeting new victims.

Source: National Cyber Security Centre