Summary
Mandiant has published attribution for an Iranian espionage campaign deploying CHOSEN BRICK, a previously undocumented Windows malware family used by APT42, the cyber arm of Iran’s Islamic Revolutionary Guard Corps Intelligence Organization. CHOSEN BRICK is designed for long-term credential harvesting and persistent surveillance against government ministries, defense contractors, diplomatic missions, and civil society organizations primarily in the Middle East and Europe. The malware establishes persistence through Windows Registry modifications, harvests credentials from browser stores and Windows Credential Manager, and exfiltrates data over encrypted channels. APT42 is the same group responsible for the 2024 campaign targeting U.S. presidential campaign staff.
Timeline
| Date | Event |
|---|---|
| Early 2026 | Mandiant first observes CHOSEN BRICK deployments against government and defense targets |
| Mid 2026 | Campaign expands; additional targets identified in Europe and the Middle East |
| Sep 17, 2026 | Mandiant publishes full attribution report linking CHOSEN BRICK to APT42/IRGC-IO; indicators of compromise released |
What Happened
CHOSEN BRICK is delivered through spearphishing emails carrying decoy documents themed around regional political and security topics relevant to the target. The initial payload dropper disguises itself as a legitimate document viewer and silently installs the main CHOSEN BRICK implant. The implant achieves persistence by writing a Registry run key and scheduling a secondary startup task as a redundant persistence mechanism.
Once established, CHOSEN BRICK harvests stored credentials from Google Chrome, Mozilla Firefox, Microsoft Edge, and Internet Explorer credential stores, as well as Windows Credential Manager entries that may include VPN credentials, domain passwords, and cloud service tokens. It also captures browser session cookies to enable account takeover without requiring the underlying password. Harvested data is staged locally in encrypted form before exfiltration over HTTPS to command-and-control infrastructure hosted across multiple countries.
APT42 is assessed by Mandiant to operate under the direction of the IRGC-IO and to conduct operations aligned with Iranian government intelligence priorities. The group’s targeting of civil society organizations and journalists in addition to government targets reflects its dual function as both a foreign intelligence collector and a domestic suppression instrument extended beyond Iranian borders.
Note on Domain Intelligence
CHOSEN BRICK is an Iranian state-sponsored malware campaign targeting government and defense organizations. No single victim domain is the subject of this bulletin. Domain intelligence for specific targeted organizations is available at warmbadge.com where those domains have been evaluated.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026