US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
Summary
US, UK, and Dutch government agencies have collaborated to expose a sophisticated surveillance malware dubbed 'Chosen Brick,' attributed to Iranian actors. The FBI's report highlights the malware's use of Telegram for command and control (C&C) operations, underscoring the evolving tactics of nation-state adversaries.
IFF Assessment
The exposure of new surveillance malware used by a nation-state actor represents a significant threat and advancement for adversaries, making it bad news for defenders.
Defender Context
This report highlights the continued threat of sophisticated surveillance malware from nation-state actors, specifically Iran. Defenders should be aware of the techniques used, particularly the abuse of popular platforms like Telegram for command and control, and strengthen monitoring and detection capabilities against such threats.