US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
Cybersecurity and intelligence agencies in the US, UK, and Netherlands have issued a joint advisory warning of a Windows malware family dubbed Chosen Brick, deployed by Iranian state cyber actors to target dissidents, activists, and journalists worldwide.
Active since at least 2025, Chosen Brick is leveraged by Iranian operators to harvest contacts, emails, social media messages, and other types of data that can be used to track an individual’s location and life patterns.
The agencies noted that the activity directly supports state-sponsored repression against individuals perceived as threats to the regime, with stolen personal information occasionally posted to pro-Iranian leak sites to harass targets.
Source: https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/
Related breach coverage
- Chosen Brick, Iran’s Surveillance Malware2026-09-17
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]
- Recent Citrix NetScaler Vulnerability Exploited in the Wild2026-08-27
CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek.
- Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover2026-09-16
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
- OpenAI Investigates Report Linking AI Agents to RubyGems Attack2026-09-15
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.