Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US, UK, Dutch Agencies Uncover Iranian Malware Threat

US, UK, Dutch Agencies Uncover Iranian Malware Threat

Posted on September 16, 2026 By CWS

Cybersecurity and intelligence bodies from the United States, United Kingdom, and the Netherlands have jointly issued an alert regarding a sophisticated Windows-based malware known as Chosen Brick. This malware, linked to Iranian state-backed cyber operatives, specifically targets dissidents, activists, and journalists on a global scale.

Background and Modus Operandi

Since at least 2025, Chosen Brick has been utilized by Iranian entities to gather extensive personal data, including contacts, emails, and social media interactions. This information aids in tracking individuals’ movements and behavioral patterns, supporting state-led repression efforts. Occasionally, the stolen data is leaked on pro-Iranian platforms to further intimidate the targets.

The infiltration process typically starts on messaging applications such as WhatsApp and Telegram. Cybercriminals gather intelligence on their targets to create a sense of trust, often masquerading as friends or technical support personnel, eventually delivering malicious files.

Techniques and Strategies

The attackers primarily target corporate devices. If initial attempts are blocked by security protocols, the attackers shift engagements to personal devices to circumvent these defenses. To deceive the victims, the malware is disguised as legitimate utility programs or falsified medical documents, such as MRI results. Once opened, the files display a decoy interface while installing the malware covertly.

Chosen Brick infections are exclusive to Windows systems. Upon activation, it ensures persistence through registry modifications and attempts to bypass local security measures by manipulating Microsoft Defender settings.

Command-and-Control and Impact

For maintaining control, the malware assigns a unique Telegram bot ID to each compromised device, ensuring operational security and preventing cross-victim data leaks. Data exfiltration is conducted via Telegram and cloud storage services.

In a separate report, the FBI has detailed the use of Telegram by Iranian hackers for command-and-control operations. Chosen Brick offers robust surveillance capabilities, such as capturing screenshots, recording audio, extracting chat data, and executing destructive commands.

Despite lacking automated lateral movement, the malware can download additional payloads, enabling expanded access through manual intervention.

As global cybersecurity threats evolve, the exposure of Chosen Brick underscores the need for enhanced vigilance and robust security measures to protect against state-sponsored cyber threats.

Security Week News Tags:CHOSEN BRICK, Cybersecurity, intelligence agencies, Iranian malware, Netherlands, state-sponsored, Surveillance, UK, US, Windows malware

Post navigation

Previous Post: N0va Phishing Campaign Challenges US and EU Security
Next Post: PAPERMILL Hackers Exploit Notepad++ to Deploy VenomRAT

Related Posts

Agentic AI Exploited in Major Ransomware Assault Agentic AI Exploited in Major Ransomware Assault Security Week News
Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin Security Week News
Signs of Concealed Information in Security Management Signs of Concealed Information in Security Management Security Week News
Signs of Concealed Information in Security Management Gitea Vulnerability Exploited Actively, Experts Alert Security Week News
EU Plans Phase Out of High Risk Telecom Suppliers, in Proposals Seen as Targeting China EU Plans Phase Out of High Risk Telecom Suppliers, in Proposals Seen as Targeting China Security Week News
New York Seeking Public Opinion on Water Systems Cyber Regulations New York Seeking Public Opinion on Water Systems Cyber Regulations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Axoflow’s AxoDetect Revolutionizes Security Data Management
  • AIUC Secures $40M to Enhance AI Agent Certification
  • Why Intelligence Alone Can’t Prevent Security Threats
  • PAPERMILL Hackers Exploit Notepad++ to Deploy VenomRAT
  • US, UK, Dutch Agencies Uncover Iranian Malware Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Axoflow’s AxoDetect Revolutionizes Security Data Management
  • AIUC Secures $40M to Enhance AI Agent Certification
  • Why Intelligence Alone Can’t Prevent Security Threats
  • PAPERMILL Hackers Exploit Notepad++ to Deploy VenomRAT
  • US, UK, Dutch Agencies Uncover Iranian Malware Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark