Iranian spies hit Windows machines with Chosen Brick data-stealing malware
- ID
- 24855
- Status
- summarized
- Published
- 16 Sep 2026, 2:01 AM
- Fetched
- 16 Sep 2026, 4:55 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 2.5
- Created
- 16 Sep 2026, 4:57 AM
- Tags
- Audience
- developersai_agent_users
What happened
Iranian state cyber actors have used the 'Chosen Brick' Windows malware since at least 2025 to surveil dissidents, activists, and journalists, according to a joint advisory from the FBI, UK NCSC, and Netherlands AIVD. Attacks begin with heavily researched WhatsApp and Telegram messages from trusted contacts, then trick victims into opening files disguised as legitimate apps including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. The malware survives reboots, adds Microsoft Defender exclusions, and uses Telegram bots for command-and-control.
Why it matters
This is targeted nation-state espionage against specific individuals, not a broad infrastructure threat. Most builders do not need to change anything based on this advisory. The only practical detail worth noting is that attackers are impersonating AI video tools (Pictory, RunwayML) and developer-adjacent software (KeePass) in social engineering lures, so teams distributing installers for AI or dev tools should be aware their brand may be spoofed in phishing campaigns.
Discussion angle
Brief mention only: nation-state actors are now using AI tool brands (Pictory, RunwayML) as malware delivery lures, which is a reputational risk for the AI tool ecosystem even if the tools themselves are not compromised.