TTO-2026-0917-134 · September 17, 2026 Nation-StateEspionage

Iranian APT42 Deploys CHOSEN BRICK Windows Malware in Espionage Campaign Against Government and Defense Targets

APT42 / Iran IRGC-IOCHOSEN BRICK malwareWindows credential harvestingGovernment and defense targetsMiddle East and EuropeMandiant attribution

Summary

Mandiant has published attribution for an Iranian espionage campaign deploying CHOSEN BRICK, a previously undocumented Windows malware family used by APT42, the cyber arm of Iran’s Islamic Revolutionary Guard Corps Intelligence Organization. CHOSEN BRICK is designed for long-term credential harvesting and persistent surveillance against government ministries, defense contractors, diplomatic missions, and civil society organizations primarily in the Middle East and Europe. The malware establishes persistence through Windows Registry modifications, harvests credentials from browser stores and Windows Credential Manager, and exfiltrates data over encrypted channels. APT42 is the same group responsible for the 2024 campaign targeting U.S. presidential campaign staff.

Timeline

DateEvent
Early 2026Mandiant first observes CHOSEN BRICK deployments against government and defense targets
Mid 2026Campaign expands; additional targets identified in Europe and the Middle East
Sep 17, 2026Mandiant publishes full attribution report linking CHOSEN BRICK to APT42/IRGC-IO; indicators of compromise released

What Happened

CHOSEN BRICK is delivered through spearphishing emails carrying decoy documents themed around regional political and security topics relevant to the target. The initial payload dropper disguises itself as a legitimate document viewer and silently installs the main CHOSEN BRICK implant. The implant achieves persistence by writing a Registry run key and scheduling a secondary startup task as a redundant persistence mechanism.

Once established, CHOSEN BRICK harvests stored credentials from Google Chrome, Mozilla Firefox, Microsoft Edge, and Internet Explorer credential stores, as well as Windows Credential Manager entries that may include VPN credentials, domain passwords, and cloud service tokens. It also captures browser session cookies to enable account takeover without requiring the underlying password. Harvested data is staged locally in encrypted form before exfiltration over HTTPS to command-and-control infrastructure hosted across multiple countries.

APT42 is assessed by Mandiant to operate under the direction of the IRGC-IO and to conduct operations aligned with Iranian government intelligence priorities. The group’s targeting of civil society organizations and journalists in addition to government targets reflects its dual function as both a foreign intelligence collector and a domestic suppression instrument extended beyond Iranian borders.

Note on Domain Intelligence

CHOSEN BRICK is an Iranian state-sponsored malware campaign targeting government and defense organizations. No single victim domain is the subject of this bulletin. Domain intelligence for specific targeted organizations is available at warmbadge.com where those domains have been evaluated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026