DEV Community

Anoymask
Anoymask

Posted on

CHOSEN BRICK: Iranian Windows Surveillance Malware Using Telegram C2

1. Overview

  • Original Title: Iranian cyber targeting of dissidents, activists and journalists
  • Source: NCSC, FBI, AIVD
  • Published: 2026-09-15
  • Updated: None
  • Severity: High
  • Basis for Severity: The joint government advisory reports real-world compromises targeting dissidents, activists, and journalists worldwide since at least 2025. The malware focuses on individual devices and can lead to the theft of sensitive communications, device wiping, and physical danger.
  • Original: Iranian cyber targeting of dissidents, activists and journalists
  • Related Sources: BleepingComputer: Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
  • Related Entities: CHOSEN BRICK, Iranian state cyber actors, Windows, Telegram, WhatsApp, Microsoft Defender, VultrObjects, StorjShare

2. Quick Summary

Iranian state-sponsored attackers pose as trusted contacts or technical support to trick users into running fake Windows apps. CHOSEN BRICK then collects communications, screen activity, and audio, sending them to Telegram or cloud storage.

3. Attack Flow

Flow 1: Spear Phishing to Surveillance and Exfiltration

  1. Attackers build trust with the target on WhatsApp or Telegram by posing as a known contact or technical support.
  2. They trick the target into running a Windows file disguised as a legitimate application or MRI results. If this fails on a corporate device, they may redirect the user to a personal device.
  3. They run CHOSEN BRICK while displaying a fake screen, setting up an HKCU Run key and a Microsoft Defender exclusion.
  4. The malware receives commands through a Telegram bot assigned specifically to that victim device and collects screens, audio, emails, and browser messages.
  5. It sends the collected data to Telegram or cloud storage based on commands. The retrieval of additional malware has also been observed. File deletion and device wiping functions have been confirmed, though this does not mean they were executed on every victim device.

4. Attacker Location and Execution Vector

  • Initial contact involves posing as a trusted person or support on messaging services.
  • After execution, attackers use Telegram bots for command and control. Collected data is sent through Telegram or cloud object storage, and newer variants use HTTPS/SOCKS5 proxies to obscure Telegram bot traffic.

5. Visibility for Victims and Administrators

Victims

  • Because a screen resembling a legitimate app or document is displayed, victims may not realize malware is running in the background.

Administrators

  • Run keys, Microsoft Defender exclusions, non-standard C:\Windows \SysWOW64 paths, and traffic to the Telegram API, storage, or proxies serve as observation points.

6. Conditions for Success and Failure

Conditions for Success

  • Initial execution requires the target to open the fake file on a Windows device without malware execution being blocked.
  • Logon persistence requires the ability to write to the HKCU Run key, and remote control via Telegram requires connectivity to the C2.
  • Adding a Microsoft Defender exclusion is a defense evasion technique. Successful exclusion addition is not treated as a mandatory prerequisite for all infections and data harvesting.

Conditions for Failure

  • Inference: If application control blocks the execution of the fake file or subsequent malware, that execution phase can be disrupted.
  • Inference: Stopping the malware and isolating the device after detection can disrupt follow-on attacker activity. Blocking Telegram traffic disrupts remote control via that C2, but it does not revert existing infections or already stolen information.

7. What Happens Upon Success

  • Emails, Telegram messages, WhatsApp messages, screen data, audio, and system information may be stolen.
  • Execution of additional malware, file deletion, and device wiping are possible.
  • Public exposure of stolen information can lead to harassment or physical danger for the targets.

8. Observable Logs

Email

  • Inference: While delivery is primarily via messaging services, check if the same fake app was also sent via email.

Proxy / SWG / DNS

  • Inference: Correlate traffic to api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net with evidence of executing processes or files. Do not assume malicious intent based solely on traffic to legitimate services.

Endpoint / EDR

  • Inference: Check for HKCU Run keys such as SMQDService and winappx, Microsoft Defender exclusions, non-standard paths, and processes associated with screen and audio capture.

Identity / IdP

  • Inference: Check for suspicious subsequent logins or session reuse involving accounts used on the device. Theft of email or browser message content alone does not establish that credentials or session tokens were stolen.

SaaS / Cloud

  • Inference: Review available session information for Telegram, WhatsApp, and email accounts for suspicious activity, along with available records of uploads to cloud storage.

Network

  • Inference: Associate continuous traffic to the Telegram API, object storage, and HTTPS/SOCKS5 proxies on a per-device basis.

9. Attack Success Determination

Criteria for Assessment in Your Organization

  • Confirm User Action: Assessment criteria: Verify through device and messaging logs that the target opened the sent file.
  • Confirm Malware Execution or Authentication Success: Assessment criteria: Substantiate CHOSEN BRICK code execution using endpoint records, cross-referencing Run keys, Microsoft Defender exclusions, and traffic to specific Telegram Bot IDs as auxiliary evidence. The absence of a Defender exclusion does not rule out infection.
  • Confirm Data Theft or Session Compromise: Assessment criteria: Confirm the creation and external transmission of screen, audio, email, and message data. The mere presence of functionality does not indicate successful theft.

10. Investigation Playbook

Trigger

  • Inference: Triggered by suspicious WhatsApp/Telegram solicitations, fake app execution, or the detection of known Run keys and samples.

Initial Check

  • Inference: Confirm the target, sender, executed file, and timestamp, and interview the user to determine if there was any redirection from a corporate device to a personal device.

Endpoints / Servers

  • Inference: Preserve execution records, HKCU Run keys, Microsoft Defender exclusions, samples, and the non-standard C:\Windows \SysWOW64 path. Also check for the trailing space after Windows.

Authentication / Cloud

  • Inference: Investigate suspicious sessions for email and messaging services used on the device. Distinguish between stolen content and account takeover.

Subsequent Operations

  • Inference: Track Telegram Bot IDs and external exfiltration per device to independently confirm the execution of additional malware, file deletion, and wiping.

Containment

  • Inference: Assist with preservation and isolation on both the target's corporate and personal devices to remove persistence and malware. Proceed with securing compromised accounts.

Judgment Categories

  • Inference: Evaluate step-by-step whether the file was opened, malware was executed, persistence was established, data was stolen, or destructive actions were taken. Do not assume total compromise based solely on available capabilities.

11. Defense and Detection Ideas

Single Event

  • Inference: Detect Microsoft Defender exclusions or HKCU Run key additions occurring close to normal software installations.

Timeline Correlation

  • Inference: Correlate the sequence of fake app execution, persistence establishment, and communication with the Telegram API, cloud storage, or proxies.

Threat Hunting

  • Inference: Search for known Run values, non-standard paths, and Telegram API and storage traffic on devices used by high-risk individuals.

Log Gaps

  • Inference: Corporate logs may not capture the initial contact or message content when personal devices, encrypted messaging, or TLS connections are involved.

Priority Countermeasures

  • Inference: Prioritize supporting high-risk users, controlling unauthorized applications, monitoring Microsoft Defender settings, and evaluating the context of Telegram and cloud service traffic.

12. Facts / Inference / Hypothesis

Facts

  • NCSC, FBI, and AIVD report that CHOSEN BRICK has targeted dissidents, activists, and journalists globally—including in the UK, US, and Netherlands—since at least 2025.
  • Attackers pose as known individuals or technical support on WhatsApp and Telegram, tricking users into running Windows files disguised as Pictory, RunwayML, Norton, Telegram, Flash, KeePass, or MRI results.
  • CHOSEN BRICK achieves persistence via an HKCU Run key, adds a Microsoft Defender exclusion, and connects to a unique Telegram Bot ID per victim device.
  • Confirmed capabilities include process and system enumeration, screen and audio capture, theft of email, Telegram, and WhatsApp data, retrieval of additional files, file deletion, and device wiping.
  • Collected data is sent to Telegram, VultrObjects, and StorjShare, while newer variants use HTTPS/SOCKS5 proxies. The advisory reports no observed automated lateral movement.

Inference

  • Because attackers may redirect targets to personal devices after initial delivery is blocked on corporate endpoints, monitoring only corporate devices may fail to capture the full scope of compromise for VIPs, public relations, research, and human rights sectors.

Hypothesis

No additional hypotheses. Unconfirmed items are listed under "Unknowns and Additional Investigation."

13. MITRE ATT&CK Mapping

  • T1566.003 Phishing: Spearphishing via Service (Confidence: high): Posing as trusted individuals or support on WhatsApp or Telegram.
  • T1204.002 User Execution: Malicious File (Confidence: high): Inducing users to open fake apps or files disguised as MRI results.
  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Confidence: high): Achieving persistence via HKCU Run keys.
  • T1102.002 Web Service: Bidirectional Communication (Confidence: high): Using Telegram bots per victim device for C2.
  • T1113 Screen Capture (Confidence: high): Screen capture functionality confirmed.
  • T1123 Audio Capture (Confidence: high): Microphone recording functionality confirmed.
  • T1485 Data Destruction (Confidence: high): File deletion and device wiping functions confirmed.

14. Unknowns and Additional Investigation

  • The complete distribution paths used to host the initial files and the specific samples executed by each victim.
  • The exact commands executed and data stolen on individual victim devices.
  • The specific organizational names and command structure of the threat actors.

15. Impact on SOCs and Organizations

Journalists, researchers, human rights activists, and diplomatic or energy personnel dealing with Iran-related matters can also become targets. Assuming potential redirection to personal devices after corporate endpoints block the attack, organizations must prepare responses that include out-of-band communication channels and direct user support.

16. Summary by Role

  • SOC: Correlate Run keys, Microsoft Defender exclusions, Telegram API, and cloud storage/proxy traffic to separately assess execution and data theft.
  • Administrators: Provide warnings and support to high-risk users, including personal devices, and restrict the execution of unauthorized software.
  • Users: Do not run applications sent via messaging apps; verify the sender through alternative channels. Be especially suspicious of requests to open files on personal devices if they fail on company devices.

Top comments (0)