Iranian hackers are targeting people described as “enemies of the state”, including dissidents, activists and journalists, with malware capable of spying on victims and stealing sensitive files, according to a joint security advisory from the UK National Cyber Security Centre, the FBI and the Netherlands’ General Intelligence and Security Service (AIVD).
The advisory says Iranian operatives research targets extensively before contacting them through social media. They may pose as someone the victim knows or as technical support, continuing the conversation until the victim’s guard is lowered.
Attackers then try to deliver malware tracked as Chosen Brick. Designed primarily for Windows, it can enumerate running processes and system information, capture screen content, enable the microphone to record audio, and copy Telegram and WhatsApp data from web browsers. It can also download additional files and malware, delete files, steal email content and ultimately wipe the computer system.
The operatives communicate with the malware using Telegram, the advisory says. The agencies said Iran almost certainly uses cyber activity to support repression of people seen as threats to the regime. They also said Iranian intelligence services have, in some cases, plotted internationally to kidnap or conduct lethal operations against people viewed as regime enemies.
Comments
0No comments yet. Be the first to comment.