MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-16 · via BleepingComputer

State-linked Iranian group deploys new Windows spyware against dissidents

Image via BleepingComputer
Image via BleepingComputer

Government agencies in the U.S., U.K., and Netherlands, along with the FBI, issued a joint advisory about a Windows malware strain called CHOSEN BRICK used by Iranian state-linked hackers. The malware steals email, Telegram, and WhatsApp data, captures screenshots, records audio, and can wipe systems, often delivered via social engineering on messaging apps. Victims are primarily dissidents, activists, and journalists, with stolen data sometimes posted on pro-Iranian leak sites to harass targets.

Expanded Detail

The joint advisory from U.S., U.K., and Dutch agencies highlights a campaign that relies heavily on social engineering through popular messaging platforms, with attackers impersonating trusted contacts or support staff. Malicious files are disguised as widely used software, and in some cases even medical documents serve as lures to gain victim trust. Once installed, the malware establishes persistence and disables Microsoft Defender protections.

The malware's capabilities extend beyond data theft to include system destruction, allowing operators to wipe entire hosts if needed. Exfiltration routes through Telegram bots and cloud storage services, with newer versions using proxy chains to obscure activity. Stolen information has reportedly been published on pro-Iranian leak sites, compounding the threat for those already at risk.

Context

This advisory underscores how state-sponsored cyber operations increasingly target individuals rather than infrastructure, using espionage tools to enable harassment and intimidation. For dissidents, activists, and journalists abroad, the threat extends beyond digital privacy to physical safety, as leaked communications could expose locations or personal networks. The involvement of multiple Western agencies suggests coordinated concern, and the malware's destructive capabilities could leave victims without access to critical data. Broader societal effects may include heightened caution among diaspora communities and increased pressure on tech platforms to harden messaging apps against such social engineering tactics.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Compromised HBO Max Reddit account used to spread info-stealing malware via fake ads · Cybersecurity
ShinyHunters leak Florida driver records after ransom demand unmet · Cybersecurity
Mantax Otax malware combines ransomware and spyware to target older Android devices · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Iranian hackers use CHOSEN BRICK Windows malware to spy on targets.” Browse more stories.