Hackers affiliated with the Iranian state are leveraging counterfeit MRI scan results to deploy CHOSEN BRICK, a type of spyware targeting Windows systems for prolonged surveillance. This campaign, identified by national cybersecurity bodies, has been active in the UK, US, and Netherlands since 2025, primarily focusing on dissidents, activists, and journalists.
Targeted Surveillance Efforts
Unlike broad financial cyber attacks, this operation demonstrates a concentrated effort on espionage. The threat lies in the attackers’ ability to persistently gather data post-infection without drawing attention. Typically, the perpetrators initiate contact through platforms like WhatsApp or Telegram, impersonating trusted contacts or support personnel to build credibility.
Once trust is established, a deceptive file is sent, disguised as a relevant document to the recipient, similar to previous malware campaigns concealed as student resumes. The UK’s National Cyber Security Centre (NCSC) has identified this tactic as part of a broader pattern of cross-border intimidation against perceived adversaries.
Technical Tactics and Implications
The attackers exploit a sense of urgency with the MRI lure, making the scam appear personal. They adapt the narrative to suit individual targets, presenting a convincing front while the actual spyware installs silently. The malware specifically targets Windows devices, leveraging the Run registry for persistence and employing antivirus exclusions to avoid detection.
This malicious software communicates with dedicated Telegram bots for each victim, complicating the identification of harmful traffic amidst legitimate online activities. Although there is no evidence of automated propagation between systems, the spyware has capabilities to download additional malicious software if required.
Protective Measures and Recommendations
Once activated, CHOSEN BRICK can execute numerous invasive actions such as capturing screenshots, recording audio, and collecting communications data from platforms like Telegram and WhatsApp. In some cases, it includes data-wiping functionalities, escalating the potential damage from these breaches.
To mitigate risks, cybersecurity experts advise against opening unexpected attachments or links, even from seemingly familiar senders. Ensuring software is sourced from official channels, keeping devices updated, and adhering to security prompts can significantly reduce vulnerability to these attacks.
Organizations should educate employees on recognizing phishing attempts and include personal devices in their security protocols. Implementing robust security measures such as multi-factor authentication and comprehensive network monitoring can further safeguard against these threats.
