The United Kingdom, the United States, and the Netherlands jointly issued a cybersecurity warning on Tuesday, September 15th. The three countries pointed out that network attackers associated with the Iranian government are currently utilizing spear-phishing and “CHOSEN BRICK” spyware to target dissidents, activists, and journalists. These attackers are attempting to deceive their targets into downloading spyware in order to track their activities.
This collaborative security alert was released by the UK’s National Cyber Security Centre (NCSC), the Federal Bureau of Investigation (FBI) of the United States, and the Dutch General Intelligence and Security Service (AIVD).
According to NCSC, CHOSEN BRICK enables attackers to gather information such as contacts, emails, social media messages of the targeted individuals, along with capabilities to capture screen content and access device microphones.
The security warning emphasizes that network attackers associated with the Iranian government impersonate contacts of the targets on messaging apps like WhatsApp and Telegram. They establish trust with the targets, deploy the CHOSEN BRICK spyware, and steal sensitive information. Dissidents, activists, and journalists worldwide perceived as threats by Iran have become targets of the CHOSEN BRICK spyware. In some instances, the Iranian intelligence has plotted overseas kidnappings of individuals deemed as enemies of the regime, even going as far as carrying out lethal operations against them.
The three countries also warn that Iranian network attackers adjust their tactics based on the specific circumstances of their intended targets, hence the initial approaches to the targets may vary. Additionally, the ultimate objectives of these cyber attackers differ. However, the attack chain usually follows the following core pattern:
– Attackers impersonate individuals or organizations trusted by the targets via social instant messaging platforms like WhatsApp and Telegram, employing social engineering techniques to establish initial contact and gain access permissions.
– Attackers disguise malicious payloads as content relevant to the deceitful context created earlier to deceive the targets into believing it as genuine.
– Malicious payloads deploy other malware, use Telegram for command and control, and blend malicious activities with legitimate processes.
– The malicious software possesses various functions that can be flexibly employed for different actions.
The security warning also notes that CHOSEN BRICK has persistence capabilities, meaning it can continue operating even after the target device is restarted.
NCSC’s Director of Operations, Paul Chichester, stated in a release that the details of this cyber operation expose Iran’s ruthless exploitation of digital surveillance means to suppress critics of the regime, including stealing emails and information, and infiltrating various devices.
