CTIPilot

CHOSEN BRICK

malware · malware:chosen-brick single-source-national-cert

Windows-only spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists and journalists in the UK, US and Netherlands; persists via the HKCU Run registry key, adds Microsoft Defender exclusions, and uses a per-victim unique Telegram Bot ID for command and control, with recent variants proxying that traffic through HTTPS/SOCKS5. Supports screen and microphone capture, Telegram/WhatsApp browser-data and email theft, and full disk wipe (joint NCSC UK/FBI/AIVD advisory, 2026-09-15).

Coverage timeline
1
first 2026-09-16 → last 2026-09-16
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
17
pinned v19.2 · see below

ATT&CK techniques

17 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1589Gather Victim Identity Information×1

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Initial Access TA0001

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Execution TA0002

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Privilege Escalation TA0004

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Stealth TA0005

T1480.002Execution Guardrails: Mutual Exclusion×1

Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is a locking mechanism used to synchronize access to a resource. Only one thread or process can acquire a mutex at a given time.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Discovery TA0007

T1057Process Discovery×1

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1114.001Email Collection: Local Email Collection×1

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1123Audio Capture×1

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Command and Control TA0011

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware · ATT&CK page ↗

Story timeline

  1. 2026-09-16CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory
    active-threatsNCSC-UK, the FBI and AIVD detail an Iranian spyware family that gives every victim their own private Telegram bot for command and control

Where this entity is cited

  • active-threats1

Source distribution

  • ncsc.gov.uk2 (67%)
  • therecord.media1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about CHOSEN BRICK (1)

2026-09-16 · view entry permalink →

NOTABLENATOA2

CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory

NCSC UK, the US FBI and the Netherlands' AIVD jointly published a technical advisory on 2026-09-15 for CHOSEN BRICK, a Windows-only malware family Iranian state cyber actors have used since at least 2025 against dissidents, activists and journalists, with confirmed victims in the UK, US and Netherlands (NCSC UK, 2026-09-15). NCSC assesses Iran "almost certainly" uses this activity to support repression of people it perceives as regime threats, and notes Iranian intelligence services have in parallel plotted kidnap or lethal operations against some of the same class of target, framing CHOSEN BRICK as a transnational-repression tool rather than conventional espionage tradecraft (NCSC UK, 2026-09-15). NCSC UK's advisory does not itself name a specific Iranian government entity, but the tradecraft closely matches activity the FBI attributed to actors operating "on behalf of the Government of Iran Ministry of Intelligence and Security" in a flash warning circulated in March 2026, which also linked a July 2025 hack-and-leak operation to the "Handala Hack" persona the FBI assesses MOIS operates and connects to a further group, "Homeland Justice" (The Record, 2026-09-15).

Access begins with extensive social-engineering rapport-building over WhatsApp or Telegram, the actor posing as a contact already known to the target or as platform technical support (T1589, T1566.003). The victim is then persuaded to download and open a file disguised as a legitimate application (observed lures include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass) or as MRI scan results (T1204.002); a decoy screen matching the lure's theme displays while the core malware installs in the background. Operators target the victim's work device first and, if delivery fails or detection risk looks high, pivot to asking the victim to open the file on a personal device instead, sidestepping corporate controls entirely. In every observed instance the malware has targeted Windows only.

CHOSEN BRICK persists across reboot via the registry Run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001), registers a mutex, commonly "ytyjyujyu" or "noi672pp434awkc12f" (T1480.002), and adds Microsoft Defender exclusions to evade detection (T1685). Command and control runs over Telegram, with each victim device assigned its own unique Telegram Bot ID as an explicit operational-security measure to prevent cross-contamination between victims (NCSC UK, 2026-09-15); newer variants layer HTTPS/SOCKS5 proxies over that channel to further obscure it (T1090.002). No automated lateral-movement capability has been observed, though the malware can download and persist additional payloads through the same registry mechanism, making it technically possible.

Tasking supports process and system enumeration (T1057, T1082), screen capture, the most commonly observed data-theft feature, used to map a victim's contacts, location and pattern of life (T1113), microphone capture (T1123), theft of Telegram/WhatsApp browser data (T1005) and email content (T1114.001), and file deletion or a full disk wipe (T1485). Collected data exfiltrates through the Telegram bot (T1041) or cloud object stores such as VultrObjects and StorjShare (T1567.002). NCSC states the most commonly observed additional-malware drop path is C:\Windows \SysWOW64, a non-standard location on most Windows installs because of the deliberate space after "Windows," which NCSC states the actor created specifically for the purpose of deploying malware; in at least one sample, this downloaded payload carried the data-wiping functionality already described above (NCSC UK, 2026-09-15). Some victims' personal data has since surfaced on pro-Iranian leak sites, which NCSC reads as a further harassment vector rather than incidental exposure (NCSC UK, 2026-09-15).

CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025.

Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.

Once established on the victim, the malware connects to Telegram for Command and Control (T1102.002). Each victim device connects to a different Telegram Bot ID unique to them as an Operational Security precaution, preventing cross-contamination between victims.

The personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected.

NCSC UK 2026-09-15
threat16 Sep 05:00Zsingle-source · national CERTOpen finding ↗