An unprecedented coalition of intelligence agencies, including the FBI, the UK's NCSC, and the Dutch AIVD, recently issued a joint warning regarding Chosen Brick. This sophisticated spyware, operated by actors affiliated with the Iranian state, poses a persistent threat to dissidents, journalists, and political activists. Far from automated mass attacks, this tool relies on a patient social engineering strategy, where operators build trust with their targets over several months before triggering the digital infection.

The modus operandi proves particularly ingenious and deceptive. Using encrypted messaging apps like WhatsApp or Telegram, the attackers pose as trusted contacts or technical support services. The trap involves tricking the victim into opening falsified documents, such as fake medical reports or booby-trapped versions of legitimate software like KeePass or Norton Antivirus. Once the Windows system is compromised, the malware embeds itself in the registry to persist after each reboot, while neutralizing Microsoft Defender’s defenses to ensure it remains invisible.

The scale of data collection carried out by Chosen Brick is alarming, turning infected devices into tools for total surveillance. The software is capable of siphoning contacts, private correspondence, live video feeds, and even remotely activating the microphone. The ultimate goal is to build an exhaustive behavioral profile of the target, known as a « pattern of life ». To avoid global detection of their infrastructure, the hackers assign a unique Telegram bot to each victim, compartmentalizing the exfiltrated information to maximize the operation's stealth.

This offensive comes against a backdrop of heightened geopolitical tensions where cyberspace has become a preferred battlefield for Iranian intelligence services, as evidenced by investigations into hacking attempts targeting high-ranking Western officials. Beyond security concerns, this threat highlights the fragility of privacy for the most exposed individuals. Faced with the constant evolution of these espionage tactics, experts reiterate that cybersecurity does not depend solely on installing protective software, but relies above all on heightened vigilance regarding digital solicitations, however familiar they may seem.