Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
Three Western governments have issued a joint warning that Iranian state cyber actors are targeting individuals using social messaging apps like WhatsApp and Telegram to deploy surveillance and data-stealing malware on their Windows machines. The malware, known as Chosen Brick, has been used by Iran since at least 2025 to take over individual devices and steal contacts, emails, and social media messages.
This allows Iranian spies to track people's movements and potentially plan kidnappings or lethal operations against perceived enemies of the regime. The attacks typically begin with seemingly legitimate messages sent via social media apps, after which attackers convince victims to download and open a malicious file. The malware then executes without the victim's knowledge, survives reboots, and connects to Telegram for command-and-control communications.
It also adds exclusions to Microsoft Defender antivirus, downloads additional malware, and attempts to evade detection. Organizations should investigate any potential infections and circulate this warning to staff who may be targeted, as Chosen Brick can target both personal and corporate devices.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.