AI Weekly Malaysia

Back to items Summaries

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

ID
24855
Status
summarized
Published
16 Sep 2026, 2:01 AM
Fetched
16 Sep 2026, 4:55 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
2.5
Created
16 Sep 2026, 4:57 AM
Tags
Audience
developersai_agent_users

What happened

Iranian state cyber actors have used the 'Chosen Brick' Windows malware since at least 2025 to surveil dissidents, activists, and journalists, according to a joint advisory from the FBI, UK NCSC, and Netherlands AIVD. Attacks begin with heavily researched WhatsApp and Telegram messages from trusted contacts, then trick victims into opening files disguised as legitimate apps including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware survives reboots, adds Microsoft Defender exclusions, and uses Telegram bots for command-and-control.

Why it matters

This is targeted nation-state espionage against specific individuals, not a broad infrastructure threat. Most builders do not need to change anything based on this advisory. The only practical detail worth noting is that attackers are impersonating AI video tools (Pictory, RunwayML) and developer-adjacent software (KeePass) in social engineering lures, so teams distributing installers for AI or dev tools should be aware their brand may be spoofed in phishing campaigns.

Discussion angle

Brief mention only: nation-state actors are now using AI tool brands (Pictory, RunwayML) as malware delivery lures, which is a reputational risk for the AI tool ecosystem even if the tools themselves are not compromised.

Top