US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

Summary

US, UK, and Dutch government agencies have collaborated to expose a sophisticated surveillance malware dubbed 'Chosen Brick,' attributed to Iranian actors. The FBI's report highlights the malware's use of Telegram for command and control (C&C) operations, underscoring the evolving tactics of nation-state adversaries.

IFF Assessment

FOE

The exposure of new surveillance malware used by a nation-state actor represents a significant threat and advancement for adversaries, making it bad news for defenders.

Defender Context

This report highlights the continued threat of sophisticated surveillance malware from nation-state actors, specifically Iran. Defenders should be aware of the techniques used, particularly the abuse of popular platforms like Telegram for command and control, and strengthen monitoring and detection capabilities against such threats.

Read Full Story →