Iranian Cyber Espionage Campaign

The actor uses this rapport with the target to convince them to download and open a file that appears authentic to the target (T1204.002). These have been in the form of applications appearing to be legitimate applications. In other instances, they have been files appearing to be MRI scan results. This installs a trojan dubbed “CHOSEN BRICK” on the victim machine. The actor often initiates contact with the target’s work-related or corporate device in the first instance. If the initial delivery fails or the risk of detection is deemed significant, the actor will attempt to transition the delivery to personal devices. “CHOSEN BRICK” appears to target single devices as the malware doesn’t include any functionality for lateral movement.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Assessment

Iran conducts extensive cyber espionage on exiled Iranian nationals and dissidents abroad. This is primarily a threat to the individual privacy of those victims. The fact that this campaign primarily appears to target their victims’ corporate devices suggests that there might be a secondary motive to steal credentials to corporate networks, however. Threat actors that work for Iran’s Revolutionary Guard Corps (IRGC) are known to conduct cybercriminal attacks in addition to espionage. Organizations worried about this malware can follow the steps in the advisory published from UK NCSC listed below.

References

https://www.ncsc.gov.uk/sites/default/files/2026-09/Advisory-Iranian-Cyber-Targeting-of-Dissidents-Activists-and-journalists.pdf

The post Iranian Cyber Espionage Campaign appeared first on Truesec.

Article Link: Iranian Cyber Espionage Campaign - Truesec