|
||
Britain, the United States and the Netherlands have disclosed a spyware campaign they attribute to Iranian state actors, detailing how malware delivered through highly targeted social engineering has been used to monitor dissidents, activists and journalists around the world.
The UK’s National Cyber Security Centre (NCSC), the FBI and the Netherlands’ General Intelligence and Security Service (AIVD) issued a joint advisory on September 15 describing a Windows malware family the NCSC calls CHOSEN BRICK. The FBI separately tracks the malware as HEAVYGRAM and attributes its use to Iran’s Ministry of Intelligence and Security (MOIS).
The campaign relies heavily on personalized deception rather than software exploits. Attackers research intended victims, then approach them through services including WhatsApp and Telegram while posing as trusted contacts or technical support. After establishing rapport, they persuade targets to open malicious files disguised as legitimate applications or documents. Observed lures have impersonated Telegram, Norton Antivirus, KeePass, Pictory and RunwayML; some were presented as MRI scan results.
The malware has been observed exclusively on Windows. Once installed, CHOSEN BRICK can establish persistence so that it survives a reboot and can add exclusions to Microsoft Defender. It communicates with its operators through Telegram bots, with a separate bot identifier used for individual victims.
Its surveillance capabilities extend well beyond stealing files. The malware can capture screenshots and microphone audio, retrieve emails and browser-accessible Telegram and WhatsApp data, enumerate system information, download additional malware and, in at least one analyzed sample, wipe data. The agencies said information collected from infected devices can reveal a victim’s contacts, location and patterns of activity.
Some stolen personal information has subsequently appeared on pro-Iranian leak sites, according to the advisory. The NCSC assesses that Iran “almost certainly” uses cyber operations to support repression of people it regards as threats. Reuters reported that Iran’s embassy in London did not immediately respond to a request for comment on the allegations.
The advisory also highlights a route around corporate security controls. Iranian operators have sometimes contacted targets initially through work devices and, when delivery failed or risked detection, encouraged them to open the files on personal computers instead. The agencies recommend that organizations whose employees may be targeted extend security awareness and compromise checks to personal devices where possible.
The NCSC has published indicators of compromise and detection guidance alongside recommendations including phishing-resistant multi-factor authentication, application allowlisting, endpoint and network monitoring, current antivirus protection and automatic software updates.
Sponsored byRadix
Sponsored byVerisign
Sponsored byWhoisXML API
Sponsored byCSC
Sponsored byDNIB.com
Sponsored byIPv4.Global
Sponsored byVerisign