Official Warning & Threat Landscape

A significant joint advisory has been issued by the Federal Bureau of Investigation (FBI) and the UK's National Cyber Security Centre (NCSC), alerting the public to a sophisticated cyber threat originating from Iranian state-linked hacking groups. These actors are actively deploying a malicious software strain known as CHOSEN BRICK, specifically targeting individuals deemed critical of the Iranian regime. The primary victims identified include dissidents, activists, and journalists operating both internationally and within countries like the United States, the United Kingdom, and the Netherlands. This advisory highlights a disturbing trend where cyber operations are used to suppress dissent and harass perceived enemies of the state, with stolen data sometimes being published on pro-Iranian leak sites to further intimidate targets.

Key Indicators Identified by Authorities

  • Social engineering tactics are employed, with attackers impersonating trusted contacts or technical support personnel to gain initial access.
  • Malicious files are disguised as legitimate applications, including popular software like Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, or even medical documents like MRI scans.
  • Victims are often tricked into running these malicious files on personal devices, sometimes under the guise of bypassing corporate security.
  • The CHOSEN BRICK malware is designed to achieve persistence on infected systems, often by manipulating Windows Registry Run keys.
  • The malware attempts to evade detection by adding exclusions to Microsoft Defender.
  • Command and control (C2) communications are established through a unique Telegram bot, often linked to the victim's ID.
  • Suspicious network connections to Telegram's API, cloud services like VultrObjects and StorjShare, and proxy services such as IPRoyal and LightningProxies are potential indicators of compromise.

Recommended Protective Measures

To safeguard against the CHOSEN BRICK malware and similar threats, individuals and organizations are strongly advised to implement robust cybersecurity practices. This includes maintaining a healthy skepticism towards unsolicited communications and attachments, even if they appear to come from known sources. Always verify the legitimacy of software downloads and be wary of requests to run unfamiliar applications. On a technical level, regularly review Registry Run entries for any suspicious entries that could indicate malware persistence. System administrators should meticulously examine logs for indicators of compromise (IoCs) that have been shared by cybersecurity agencies. Furthermore, monitoring network traffic for unusual connections to the services mentioned in the advisory is crucial. Keeping operating systems and security software up-to-date is a fundamental step in patching vulnerabilities that threat actors exploit. For those in high-risk professions, such as journalism or activism, consider using end-to-end encrypted communication tools and practicing strict digital hygiene.