CHOSEN BRICK Windows Malware (Iranian State-Sponsored Espionage)
First seen Sep 17, 2026 · Updated Sep 17, 2026
Government agencies have issued warnings about CHOSEN BRICK, a Windows malware strain attributed to Iranian state-linked threat actors used to surveil dissidents, activists, and journalists globally. The campaign appears focused on intelligence collection and targeting of civil society figures rather than financial gain or broad enterprise compromise.
Technical Analysis
CHOSEN BRICK is a Windows-based espionage malware deployed by Iranian state-linked actors, likely delivered via spearphishing, social engineering, or targeted exploitation given the profile of victims (dissidents, journalists, activists). The malware's specific capabilities (keylogging, credential theft, exfiltration, C2 communication) are not fully detailed in available reporting, but it aligns with prior Iranian APT toolsets used for long-term surveillance and monitoring of high-value human targets. No CVE has been publicly attributed to the initial infection vector, suggesting reliance on social engineering rather than a novel exploit chain. Given the campaign's focus on individuals rather than enterprise infrastructure, direct impact to AI agent systems is currently low, though any credential or session-token theft from compromised endpoints could expose API keys or tokens used by agent-based tools if victims utilize such systems on infected hosts.
Affected Systems
Microsoft Windows endpoints belonging to targeted individuals (dissidents, journalists, activists); specific OS versions not disclosed in current reporting
Indicators of Compromise
- No specific hashes, IPs, or domains provided in source reporting; monitor official CISA/NCSC/FBI advisories for updated IOC lists related to CHOSEN BRICK
Remediation Steps
- 1
Monitor official advisories
Track CISA, FBI, and allied government agency bulletins for updated IOCs and detection signatures related to CHOSEN BRICK.
- 2
Endpoint detection tuning
Deploy EDR rules to detect anomalous process injection, persistence mechanisms, and unusual outbound connections on Windows endpoints used by high-risk individuals.
- 3
High-risk user protection
Provide enhanced security training and hardened device configurations to journalists, activists, and dissidents who may be targeted.
- 4
Credential hygiene
Rotate credentials and API keys on any endpoint suspected of compromise, particularly those used to access cloud services, email, or automation/agent tooling.
- 5
Network segmentation and MFA
Enforce multi-factor authentication and restrict lateral movement paths in case of initial compromise.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.