
Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad
A sophisticated Iranian threat actor is targeting nationals living abroad using social engineering on messaging platforms. The campaign delivers a custom trojan, 'CHOSEN BRICK', disguised as legitimate files.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Middle East
- Confidence:
- High Confidence
- MITRE ID:
- T1204.002
- Source:
- Truesec
- Read Time:
- 4 min
Executive Summary
As of September 23, 2026, intelligence reports have identified a targeted cyber-espionage campaign originating from Iranian threat actors. The operation focuses on Iranian nationals residing outside the country, utilizing social engineering tactics via encrypted messaging applications to facilitate the deployment of a custom-built trojan identified as 'CHOSEN BRICK'.
Threat Analysis
The campaign relies heavily on the establishment of rapport between the attacker and the victim. Threat actors initiate contact on platforms such as Telegram or WhatsApp, often masquerading as acquaintances or technical support representatives from the messaging service itself. By leveraging this perceived trust, the attackers manipulate victims into executing malicious files under the guise of legitimate software or personal documents, such as medical records or MRI scan results.
Technical Details
The primary payload, 'CHOSEN BRICK', is designed for stealthy exfiltration and persistent access. Upon execution, the malware establishes a foothold on the victim's machine, utilizing techniques categorized under T1204.002 (User Execution: Malicious File). The malware is specifically crafted to bypass standard endpoint detection by mimicking the behavior and appearance of benign applications. Once installed, it provides the operators with remote access capabilities, allowing for the monitoring of communications and the theft of sensitive data from the compromised host.
Attribution Assessment
While the specific identity of the threat actor remains under investigation, the tactics, techniques, and procedures (TTPs) align with known Iranian state-sponsored espionage operations. The focus on specific diaspora populations and the use of custom-developed malware suggest a well-resourced entity with clear intelligence-gathering objectives consistent with regional state interests.
Implications
This campaign highlights the ongoing risk to individuals living abroad who may be perceived as targets by their home governments. The use of highly personalized social engineering demonstrates an evolution in how state-sponsored actors conduct surveillance, moving beyond traditional network-based attacks to direct, human-centric manipulation. The potential for this malware to be used for long-term monitoring poses a significant threat to the privacy and safety of the targeted individuals.
Recommendations
- Exercise extreme caution when receiving unsolicited messages from unknown or even familiar contacts on messaging platforms, especially if they request the download of files.
- Verify the identity of any individual claiming to be technical support through official, secondary channels.
- Implement robust endpoint security solutions capable of detecting behavioral anomalies associated with trojanized applications.
- Regularly update and patch all software to mitigate the risk of exploitation if the initial social engineering attempt fails.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

New Iranian Cyber Espionage Campaign Targets Global Dissidents and Journalists

NightEagle APT Escalates Cyber Espionage Campaign Against Russian Critical Infrastructure

