News Room
16
Share
Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad
highCyber Espionage

Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad

A sophisticated Iranian threat actor is targeting nationals living abroad using social engineering on messaging platforms. The campaign delivers a custom trojan, 'CHOSEN BRICK', disguised as legitimate files.

27 September 2026Last updated 27 September 20264 min readTruesec
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Middle East
Confidence:
High Confidence
MITRE ID:
T1204.002
Source:
Truesec
Read Time:
4 min

Executive Summary

As of September 23, 2026, intelligence reports have identified a targeted cyber-espionage campaign originating from Iranian threat actors. The operation focuses on Iranian nationals residing outside the country, utilizing social engineering tactics via encrypted messaging applications to facilitate the deployment of a custom-built trojan identified as 'CHOSEN BRICK'.

Threat Analysis

The campaign relies heavily on the establishment of rapport between the attacker and the victim. Threat actors initiate contact on platforms such as Telegram or WhatsApp, often masquerading as acquaintances or technical support representatives from the messaging service itself. By leveraging this perceived trust, the attackers manipulate victims into executing malicious files under the guise of legitimate software or personal documents, such as medical records or MRI scan results.

Technical Details

The primary payload, 'CHOSEN BRICK', is designed for stealthy exfiltration and persistent access. Upon execution, the malware establishes a foothold on the victim's machine, utilizing techniques categorized under T1204.002 (User Execution: Malicious File). The malware is specifically crafted to bypass standard endpoint detection by mimicking the behavior and appearance of benign applications. Once installed, it provides the operators with remote access capabilities, allowing for the monitoring of communications and the theft of sensitive data from the compromised host.

Attribution Assessment

While the specific identity of the threat actor remains under investigation, the tactics, techniques, and procedures (TTPs) align with known Iranian state-sponsored espionage operations. The focus on specific diaspora populations and the use of custom-developed malware suggest a well-resourced entity with clear intelligence-gathering objectives consistent with regional state interests.

Implications

This campaign highlights the ongoing risk to individuals living abroad who may be perceived as targets by their home governments. The use of highly personalized social engineering demonstrates an evolution in how state-sponsored actors conduct surveillance, moving beyond traditional network-based attacks to direct, human-centric manipulation. The potential for this malware to be used for long-term monitoring poses a significant threat to the privacy and safety of the targeted individuals.

Recommendations

  1. Exercise extreme caution when receiving unsolicited messages from unknown or even familiar contacts on messaging platforms, especially if they request the download of files.
  2. Verify the identity of any individual claiming to be technical support through official, secondary channels.
  3. Implement robust endpoint security solutions capable of detecting behavioral anomalies associated with trojanized applications.
  4. Regularly update and patch all software to mitigate the risk of exploitation if the initial social engineering attempt fails.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo