Cybersecurity Threats from Iranian State Actors
Recent advisories from three Western governments have shed light on the alarming tactics employed by Iranian state cyber actors. These entities are reportedly targeting individuals through popular social messaging applications, deploying surveillance and data-stealing malware specifically designed for Windows systems. Dubbed “Chosen Brick,” this malware has been in use since at least 2025, enabling the theft of personal data such as contacts, emails, and social media messages. This capability allows Iranian spies to monitor the movements of those they perceive as threats, including dissidents, activists, and journalists.
The advisory, issued by the FBI, the UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD), emphasizes that Iran likely employs cyber operations to bolster its repression of individuals deemed adversarial to the regime. In extreme cases, Iranian intelligence services have even plotted kidnappings or lethal operations against these perceived enemies on an international scale.
The modus operandi of these attacks typically initiates with messages sent via WhatsApp or Telegram, masquerading as communications from known and trusted contacts. The attackers conduct thorough research on their targets, amassing extensive knowledge about the individual, their connections, and relevant organizations. This groundwork is crucial for crafting convincing messages that establish a sense of trust.
Once rapport is built, the attackers persuade the victim to download and execute a file that appears to be a legitimate application. Notable programs that have been mimicked include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. Upon execution, the malware operates stealthily, surviving system reboots and evading detection by modifying settings in Microsoft Defender antivirus. It then establishes a connection to Telegram for command-and-control communications, utilizing a victim-specific bot.
While the malware has not yet demonstrated the capability to automate lateral movement across networks, the advisory indicates that such functionality is technically feasible. Infected devices may also experience the download of additional malware and the establishment of persistence for new payloads, leveraging the same registry key used by Chosen Brick to maintain its foothold on Windows systems.
Additional features of Chosen Brick include the ability to enumerate running processes, capture screen and audio content, and extract sensitive information from emails and web browsers, particularly targeting data from Telegram and WhatsApp. In a concerning twist, the malware can even wipe the infected computer system.
Organizations that suspect they may have been compromised by Chosen Brick are urged to engage their IT providers—whether internal or external—to conduct thorough investigations. Given that these cyber threats are not limited to corporate devices, it is recommended that organizations disseminate this information among staff who may be at risk and assist them in checking their personal devices for potential compromises.
This latest alert regarding Iranian cyber activities follows a series of cyberattacks on water and energy sectors, which researchers and media reports have linked to Iran. Although the US and UK governments have refrained from formally attributing these attacks, the ongoing military conflict between Iran and the US continues to escalate, raising concerns about the implications for cybersecurity.
In August, the Cybersecurity and Infrastructure Security Agency (CISA) revealed that cyberattacks in July disrupted water utilities across 12 states, targeting over 100 internet-exposed water systems. However, CISA did not attribute these incidents to Iran or any other entity. Concurrently, a suspected Iran-linked cyberattack led to the shutdown of a small power plant in the UK.
Moreover, five US agencies have warned that attackers are employing AI-generated exploitation scripts to infiltrate internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical facilities in water, manufacturing, and energy sectors. This situation underscores the reality that the threat is not merely theoretical; it is an active and pressing concern for organizations worldwide.