CuraSec

Learn active

Iranian APT deploys CHOSEN BRICK Windows spyware against dissidents

2026-09-17 15:32 UTC · BleepingComputer · read the source ↗ #iranian-apt#windows-malware#espionage
  • Engineer — Learn: No enrichment signals and the targeting profile (dissidents, journalists, activists) is outside typical enterprise attack surface; no patch, configuration, or supply-chain action indicated.
  • SOC/IR — Learn: Government-issued warning about a named Windows malware family is useful actor-context, but the summary provides no IOCs, ATT&CK TTPs, or detection artifacts to act on; revisit if a follow-up report publishes indicators.
  • Leader — Learn: Iranian state espionage campaign is worth noting for sector risk registers, especially for media, NGO, or policy-adjacent organizations, but no vendor exposure, regulatory trigger, or board-level event is present here.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.