Cybersecurity Threats from Iranian Hackers
Recent reports indicate that Iranian state-sponsored hackers have been employing deceptive tactics to target dissidents, activists, and journalists. These hackers are allegedly using malicious applications that masquerade as reputable cybersecurity products, including Norton Antivirus and the password manager KeePass, to surreptitiously install Windows-based spyware on victims’ devices.
On Tuesday, both the FBI and the UK authorities issued a warning to the public regarding this emerging threat. According to the FBI’s advisory, the initial approach taken by these hackers involves establishing a rapport with their targets through social messaging platforms, where they often pose as IT customer support representatives or even impersonate known contacts.
“The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target,” the FBI elaborated. The malicious bait has included AI video creation applications like Pictory and RunwayML, alongside well-known software such as Norton Antivirus, KeePass, the messaging app Telegram, and Adobe Flash Player. In a particularly alarming tactic, the hackers have also utilized fabricated MRI test results to phish their targets.
The spyware in question, dubbed “Chosen Brick,” is specifically designed to infect desktop PCs rather than mobile devices. The FBI noted, “In all observed instances, the malware has been exclusively targeted at the Windows operating system.” Once installed, the spyware boasts a range of capabilities, including:
- Capturing screen content
- Accessing the microphone to record audio
- Collecting message data from web browsers
- Downloading additional malware components
In some cases, the hackers have exploited the screen-capturing function to publish personal details of victims, further exacerbating the harassment they face. The overarching aim appears to be the suppression of individuals who oppose the Iranian regime. The UK’s National Cyber Security Centre has noted that personal information from previous victims of Chosen Brick has surfaced on pro-Iranian leak sites, heightening the risk to their safety.
In light of these developments, the FBI has provided guidance for potential victims on how to detect the spyware, which has been known to evade Windows Defender. While the agency did not provide specific instructions for removal, it suggested that a full factory reset could eliminate the threat. Additionally, the FBI recommended that users enable antivirus or anti-malware software on their devices, run scans regularly, and steer clear of downloading applications from unofficial sources.