Chosen Brick: Iranian Malware Uses Telegram to Spy on Dissidents, Journalists, and Activists
What Happened – The UK NCSC, the U.S. FBI, and the Dutch AIVD issued a joint advisory describing “Chosen Brick,” a Windows‑based malware family employed by Iranian intelligence services. Since 2025 the malware has been delivered through Telegram, harvesting contacts, emails and social‑media messages from targeted individuals worldwide.
Why It Matters for Trust & Control Assurance
- Continuous monitoring programs must surface malicious command‑and‑control traffic on consumer platforms (e.g., Telegram) before data exfiltration occurs.
- Defensible audit evidence of detection, containment, and forensic analysis is essential when state‑sponsored actors turn a compromised laptop into a physical‑harassment vector.
Who Is Affected – Human‑rights journalists, political dissidents, NGOs and other civil‑society actors in the UK, US, the Netherlands and globally.
Recommended Actions
- Integrate outbound‑traffic analytics for popular messaging apps into your security monitoring stack.
- Conduct targeted phishing and malware‑awareness drills that simulate Telegram‑borne payloads.
- Document incident‑response playbooks that cover evidence preservation for state‑actor investigations.
Source: Security Affairs
Technical Notes – The payload is a Windows executable delivered via malicious Telegram links; it extracts contacts, email archives and social‑media messages, then uploads them to Iranian command servers. No public CVE is associated. Source: same