CHOSEN BRICK Malware Exposes the Growing Risk of Targeted Cyber Espionage

Cybersecurity threats are becoming increasingly personalized.

Attackers are no longer relying only on automated phishing campaigns or broad malware distribution. Sophisticated threat actors are researching individuals, building trust through familiar communication channels, and using carefully tailored lures to gain access to devices and sensitive information.

A recent joint advisory from the UK National Cyber Security Centre, the US Federal Bureau of Investigation, and the Netherlands General Intelligence and Security Service has highlighted a Windows malware family known as CHOSEN BRICK.

The agencies report that the malware has been used against individuals including dissidents, activists, and journalists in multiple countries. The campaign demonstrates how social engineering, spyware, legitimate online services, and targeted intelligence gathering can be combined into a highly personalized cyberattack.

Why CHOSEN BRICK Matters

CHOSEN BRICK is particularly concerning because the malware is only one part of the broader attack chain.

The reported campaigns begin with social engineering.

Threat actors have used platforms such as WhatsApp and Telegram to establish communication with targets while presenting themselves as trusted contacts or legitimate sources of assistance.

The attackers then tailor malicious files to the individual being targeted.

Reported lures have included files designed to resemble legitimate applications, technical tools, and documents relevant to the target. In some cases, the agencies identified malicious files presented as medical imaging results.

This approach demonstrates an important cybersecurity principle:

Trust can become an attack surface.

When a malicious file appears to come from someone familiar or relates directly to a person’s interests or circumstances, traditional assumptions about phishing can become less effective.

How the Campaign Operates

According to the joint advisory, the campaign follows a flexible attack pattern.

The reported sequence generally involves:

• Researching the intended target

• Establishing contact through messaging platforms

• Building credibility and rapport

• Delivering a personalized malicious file

• Executing malware on a Windows device

• Establishing persistence

• Collecting information from the compromised system

• Using online services for command and control

• Exfiltrating sensitive information

The malware has been observed communicating through Telegram, allowing the attackers to use a widely available communication platform as part of their command and control infrastructure.

This illustrates why organizations cannot evaluate malicious activity only by looking for obviously suspicious infrastructure.

Attackers may attempt to hide within services that employees already use every day.

The Information at Risk

The capabilities described by the agencies show why targeted spyware can create significant privacy and security consequences.

CHOSEN BRICK can collect information including:

• Contacts

• Email content

• Social media information

• Messaging data

• Screen content

• System information

• Audio through the device microphone

The malware can also download additional malicious software and perform other actions on an infected Windows system.

Screen captures can be particularly valuable to an attacker because they may reveal more than a single piece of information.

A screenshot could expose communications, documents, account information, application activity, location information, or details about a person’s professional and personal relationships.

This makes endpoint compromise a potential gateway to broader intelligence collection.

The Human Element Remains Critical

One of the most important lessons from this campaign is that cybersecurity cannot depend entirely on technical controls.

The attack begins by influencing human behavior.

Threat actors research their targets and then construct scenarios that make malicious activity appear reasonable.

This can make conventional security awareness messages less effective if they focus only on obvious warning signs.

Security training should instead teach users to recognize behavioral patterns such as:

• Unexpected requests from familiar contacts

• Messages that create urgency or emotional pressure

• Unusual requests to install software

• Files received outside normal business processes

• Links or attachments that require immediate action

• Requests to move conversations to another platform

• Requests to use personal devices for work related activities

• Unusual requests involving confidential information

Security awareness should also be reinforced through technical controls rather than placing responsibility entirely on employees.

Why Personal Devices Matter

The advisory highlights another important challenge.

Threat actors may initially approach targets through work related devices but can attempt to move the interaction toward personal devices when corporate security controls make the attack more difficult.

This creates a major security visibility problem for organizations.

A company may have strong endpoint protection, email security, identity controls, and network monitoring across corporate infrastructure while having very limited visibility into the personal device used by an employee or executive.

Organizations should therefore establish clear policies around:

• Use of personal devices for sensitive work

• Corporate access from unmanaged endpoints

• Mobile and messaging application usage

• Authentication requirements

• Sensitive data handling

• Incident reporting

• Secure communication channels

Persistence Makes Endpoint Security Even More Important

The joint advisory states that CHOSEN BRICK can remain active after a Windows system is restarted.

The malware has also been observed modifying security settings to make detection more difficult.

This reinforces the importance of monitoring endpoint security health rather than simply deploying an antivirus or EDR product.

Security teams should continuously evaluate whether:

• Endpoint protection remains active

• Security policies have been modified

• Unexpected persistence mechanisms exist

• Suspicious processes are running

• Unusual applications are communicating externally

• Security exclusions have changed

• Devices are communicating with unexpected services

• Authentication activity matches normal user behavior

An endpoint that suddenly stops reporting security telemetry should itself become a security signal.

Identity Security Is Part of the Defense

Modern spyware campaigns also demonstrate why identity security needs to extend beyond passwords.

If malware gains access to an employee’s device, attackers may attempt to obtain information that can be used to access additional accounts.

Organizations should therefore combine endpoint security with:

• Multi factor authentication

• Strong identity verification

• Conditional access

• Privileged access management

• Least privilege

• Session monitoring

• Short lived credentials

• Device compliance checks

• Risk based authentication

Identity controls should also account for compromised endpoints.

A valid account session does not necessarily mean that the device or user activity is trustworthy.

Messaging Platforms Can Become Part of the Attack Surface

WhatsApp and Telegram are legitimate communication platforms used by millions of people.

The problem is not the existence of these platforms.

The security concern arises when attackers use familiar communication channels to establish trust and deliver malicious content.

Organizations should therefore consider messaging applications within broader security awareness and threat monitoring strategies.

Security teams should educate employees about the risks of:

• Unexpected files from known contacts

• New contacts claiming to be colleagues or support personnel

• Requests to install applications

• Links received through informal communication channels

• Requests to continue business conversations on personal accounts

• Unusual communications involving confidential information

The same principle applies to collaboration platforms, social networks, email, and other digital communication channels.

Protecting High Risk Individuals

Some organizations have employees who are more likely to be targeted because of their roles, public visibility, access privileges, or the information they handle.

These can include:

• Executives

• Security leaders

• Researchers

• Journalists

• Government personnel

• Legal teams

• Financial teams

• Engineers

• Administrators

• Public facing employees

Organizations should consider additional security protections for high risk individuals rather than applying identical security controls to every user.

Additional protections can include stronger authentication, hardened devices, enhanced monitoring, dedicated security support, secure communication procedures, and targeted security awareness training.

What Organizations Should Do

The CHOSEN BRICK campaign provides several practical security lessons for organizations.

1. Strengthen Endpoint Protection

Ensure Windows devices have current security updates, properly configured endpoint protection, and centralized monitoring.

2. Monitor Security Control Changes

Unexpected changes to endpoint security configurations should generate investigation signals.

3. Improve Phishing Resistance

Security awareness programs should include highly personalized social engineering scenarios rather than focusing only on generic phishing emails.

4. Protect High Risk Users

Executives, administrators, researchers, and other high value targets should receive additional security controls based on their risk profile.

5. Enforce Strong Authentication

Use phishing resistant authentication where practical and apply conditional access policies based on device and session risk.

6. Monitor Unusual Communication Patterns

Security teams should investigate unexpected communication between corporate endpoints and external services that are not normally required for business activity.

7. Secure Personal Device Access

Organizations should establish clear controls for accessing corporate resources from unmanaged or personal devices.

8. Maintain Incident Response Readiness

Security teams should have procedures for isolating compromised devices, investigating persistence, protecting accounts, and determining whether sensitive information was accessed.

9. Continuously Test Security Controls

Penetration testing, social engineering assessments, endpoint security validation, and threat simulations can help identify weaknesses before real attackers exploit them.

Industries That Need Stronger Protection

The risks highlighted by CHOSEN BRICK extend beyond journalism and civil society.

Financial Services

Banks, insurance companies, fintech organizations, and investment firms manage highly sensitive financial information and valuable employee identities.

COE Security can help financial organizations strengthen endpoint security, identity protection, phishing resilience, application security, network monitoring, penetration testing, and compliance programs.

Healthcare

Healthcare organizations manage sensitive patient information and rely on large numbers of employees, contractors, medical systems, and connected devices.

COE Security can help healthcare organizations strengthen endpoint and application security, protect sensitive information, assess third party risks, and support HIPAA aligned security programs.

Retail and E-commerce

Retail organizations depend on customer applications, payment systems, cloud platforms, APIs, employee accounts, and third party services.

COE Security can help assess application, API, identity, cloud, endpoint, and network security while strengthening protection of customer and payment related information.

Manufacturing

Manufacturers increasingly connect enterprise systems, engineering environments, cloud services, connected devices, and operational technology.

A compromised employee endpoint can create risks that extend beyond traditional IT.

COE Security can help manufacturers strengthen endpoint protection, network security, application security, cloud environments, and relevant IT and OT security controls.

Government and Public Sector

Government organizations can be attractive targets because they manage sensitive information, public services, and high value digital infrastructure.

COE Security can support government organizations through penetration testing, threat monitoring, identity security, application security, cloud security, secure development practices, and compliance focused assessments.

Building a More Resilient Security Strategy

CHOSEN BRICK is another reminder that modern cyber defense needs to operate across multiple layers.

A resilient security program should combine:

• Endpoint security

• Identity security

• Network monitoring

• Threat intelligence

• Security awareness

• Application security

• Cloud security

• Data protection

• Vulnerability management

• Incident response

• Continuous security testing

No single technology can eliminate the risk of a well researched social engineering campaign.

The objective should instead be to create multiple defensive barriers so that failure at one layer does not automatically result in a successful compromise.

Conclusion

The CHOSEN BRICK campaign highlights how modern cyber espionage can combine social engineering, personalized deception, endpoint malware, legitimate communication platforms, and targeted data collection.

The joint advisory from the UK, US, and Dutch agencies also demonstrates the importance of sharing technical intelligence about emerging threats so organizations and individuals can improve their defenses.

The most important lesson is that cybersecurity is not only about detecting malicious software.

Organizations must also understand how attackers establish trust, manipulate human behavior, compromise endpoints, abuse legitimate services, and move toward sensitive information.

Strong identity controls, secure endpoints, continuous monitoring, security awareness, threat detection, and regular security testing can help organizations reduce exposure to increasingly targeted cyber threats.

As threat actors become more sophisticated in their use of social engineering and surveillance malware, organizations should treat human behavior, endpoints, identities, and communication platforms as interconnected parts of the security landscape.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations strengthen their security posture against targeted cyber threats through endpoint security assessments, phishing and social engineering assessments, identity and access management reviews, application security testing, network security assessments, cloud security assessments, threat monitoring, vulnerability management, incident response planning, and penetration testing.

For financial services organizations, we help protect sensitive financial applications, employee identities, customer information, APIs, cloud infrastructure, and critical business systems through security assessments, penetration testing, threat monitoring, and compliance focused security programs.

For healthcare organizations, we help secure systems handling sensitive patient information, connected technologies, cloud platforms, applications, endpoints, and third party environments while supporting HIPAA aligned cybersecurity practices.

For retail and e-commerce organizations, we help protect customer facing applications, payment environments, APIs, employee accounts, cloud platforms, and third party integrations through application security testing, identity assessments, cloud security reviews, and continuous security monitoring.

For manufacturing organizations, we help strengthen security across enterprise applications, endpoints, networks, cloud infrastructure, connected systems, and relevant IT and OT environments to reduce the risk of compromise and operational disruption.

For government organizations, we help strengthen endpoint, identity, application, network, cloud, and data security while supporting penetration testing, threat monitoring, vulnerability management, secure development, and compliance requirements.

COE Security also helps organizations prepare for targeted cyber threats through security awareness programs, high risk user assessments, incident response planning, threat detection, security architecture reviews, and continuous security validation.

As cyber threats become increasingly personalized and attackers use legitimate communication channels to establish trust, organizations need security strategies that combine technology, people, processes, and continuous monitoring.

Follow COE Security on LinkedIn for ongoing insights into cybersecurity, AI security, application security, threat intelligence, compliance, emerging threats, and secure digital transformation. Stay updated and cyber safe.

Click to read our LinkedIn feature article