LIVE · cybersecurity feed
Live wire
Cisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
malware

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

zeroday.news ·

The intelligence services of Iran are employing a Windows-based malware family, dubbed Chosen Brick, to surveil and harass dissidents, journalists, and activists globally, according to a joint advisory issued by the UK’s National Cyber Security Centre (NCSC), the U.S. Federal Bureau of Investigation (FBI), and the Netherlands’ AIVD. This malware has been active since at least 2025, enabling Iranian state-sponsored cyber actors to gather sensitive information, including contacts, emails, and social media messages, which could facilitate tracking of victims’ movements.

The advisory highlights that the risks for victims extend beyond cyber intrusion. Personal information obtained through Chosen Brick has reportedly appeared on pro-Iranian leak sites, potentially exposing individuals to further harassment, intimidation, or physical threats. The agencies noted that Iranian intelligence services have previously been linked to plots involving kidnapping or lethal operations against perceived opponents abroad.

The attack methodology typically begins with social engineering via messaging applications like WhatsApp or Telegram. Iranian cyber actors engage with targets, sometimes for extended periods, to build rapport and trust. This social engineering is highly tailored, leveraging detailed information gathered through prior reconnaissance. Attackers may impersonate individuals known to the target or pose as technical support staff from the messaging platform to enhance credibility.

After establishing trust, the attackers attempt to deliver the malware through lure files disguised as legitimate software installers or documents. Examples include fake installers for applications such as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, or KeePass. In some instances, the lure files have been disguised as MRI scan results. Upon opening, these files display a convincing decoy screen while the Chosen Brick payload installs silently in the background, granting attackers control over the compromised Windows device.

Chosen Brick establishes persistence on infected systems by creating a registry Run key, ensuring it survives system reboots. It also attempts to add exclusions to Microsoft Defender to evade detection. The malware has exclusively been observed targeting Windows systems.

The attackers often initially target a victim's work device. However, if this attempt fails or if they suspect detection, they may pivot to targeting personal devices, asking victims to open the malicious file on their personal phones or computers, thereby bypassing corporate security controls. This strategy underscores the challenge for organizations in securing personal devices used by employees, which typically fall outside the scope of corporate IT oversight.

This is not the first instance of Iranian state-linked actors using Telegram-based malware against the Iranian diaspora. In March, the FBI reported similar activity dating back to late 2023, where Iranian actors utilized Telegram as command infrastructure to target dissidents. The recent joint advisory provides a formal name, joint attribution, and a more detailed operational overview of the malware, consolidating information that security researchers had previously tracked under various names.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Smashing Security podcast #485: These researchers got drunk to hack an LG TV

Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhi

vulnerabilityhigh

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

vulnerability

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

finance

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]

ai

AI agents can modify themselves without humans telling them to do so

This is a test - it is only a test

ai

AI Security Spending Jumps as Fear Outpaces Proof of Value

CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?