Learn
active
Iranian APT deploys CHOSEN BRICK Windows spyware against dissidents
- Engineer — Learn: No enrichment signals and the targeting profile (dissidents, journalists, activists) is outside typical enterprise attack surface; no patch, configuration, or supply-chain action indicated.
- SOC/IR — Learn: Government-issued warning about a named Windows malware family is useful actor-context, but the summary provides no IOCs, ATT&CK TTPs, or detection artifacts to act on; revisit if a follow-up report publishes indicators.
- Leader — Learn: Iranian state espionage campaign is worth noting for sector risk registers, especially for media, NGO, or policy-adjacent organizations, but no vendor exposure, regulatory trigger, or board-level event is present here.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.