Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware

Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware

Posted on September 16, 2026 By CWS

Hackers affiliated with the Iranian state are leveraging counterfeit MRI scan results to deploy CHOSEN BRICK, a type of spyware targeting Windows systems for prolonged surveillance. This campaign, identified by national cybersecurity bodies, has been active in the UK, US, and Netherlands since 2025, primarily focusing on dissidents, activists, and journalists.

Targeted Surveillance Efforts

Unlike broad financial cyber attacks, this operation demonstrates a concentrated effort on espionage. The threat lies in the attackers’ ability to persistently gather data post-infection without drawing attention. Typically, the perpetrators initiate contact through platforms like WhatsApp or Telegram, impersonating trusted contacts or support personnel to build credibility.

Once trust is established, a deceptive file is sent, disguised as a relevant document to the recipient, similar to previous malware campaigns concealed as student resumes. The UK’s National Cyber Security Centre (NCSC) has identified this tactic as part of a broader pattern of cross-border intimidation against perceived adversaries.

Technical Tactics and Implications

The attackers exploit a sense of urgency with the MRI lure, making the scam appear personal. They adapt the narrative to suit individual targets, presenting a convincing front while the actual spyware installs silently. The malware specifically targets Windows devices, leveraging the Run registry for persistence and employing antivirus exclusions to avoid detection.

This malicious software communicates with dedicated Telegram bots for each victim, complicating the identification of harmful traffic amidst legitimate online activities. Although there is no evidence of automated propagation between systems, the spyware has capabilities to download additional malicious software if required.

Protective Measures and Recommendations

Once activated, CHOSEN BRICK can execute numerous invasive actions such as capturing screenshots, recording audio, and collecting communications data from platforms like Telegram and WhatsApp. In some cases, it includes data-wiping functionalities, escalating the potential damage from these breaches.

To mitigate risks, cybersecurity experts advise against opening unexpected attachments or links, even from seemingly familiar senders. Ensuring software is sourced from official channels, keeping devices updated, and adhering to security prompts can significantly reduce vulnerability to these attacks.

Organizations should educate employees on recognizing phishing attempts and include personal devices in their security protocols. Implementing robust security measures such as multi-factor authentication and comprehensive network monitoring can further safeguard against these threats.

Cyber Security News Tags:AIVD, CHOSEN BRICK, cyber attack, Cybersecurity, data breach, fake MRI, FBI, Iranian hackers, NCSC, online security, Phishing, Spyware, Surveillance, Telegram, WhatsApp

Post navigation

Previous Post: Acronis Urgently Fixes Vulnerability in cPanel Plugin
Next Post: Data Breach Affects 280,000 at Premier Medical Group

Related Posts

Cisco Warns of Severe Email Gateway Security Flaw Cisco Warns of Severe Email Gateway Security Flaw Cyber Security News
PlugX USB Worm Exploits DLL Sideloading Globally PlugX USB Worm Exploits DLL Sideloading Globally Cyber Security News
Google Blogger Mistakenly Flags Safe Websites as Malware Google Blogger Mistakenly Flags Safe Websites as Malware Cyber Security News
OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks Cyber Security News
25 Controls, Mapped And Audit-Ready 25 Controls, Mapped And Audit-Ready Cyber Security News
Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top AWS Security Tools for 2026: A Comprehensive Guide
  • Data Breach Affects 280,000 at Premier Medical Group
  • Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware
  • Acronis Urgently Fixes Vulnerability in cPanel Plugin
  • Microsoft Issues Urgent Update for Windows 11 Bugs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top AWS Security Tools for 2026: A Comprehensive Guide
  • Data Breach Affects 280,000 at Premier Medical Group
  • Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware
  • Acronis Urgently Fixes Vulnerability in cPanel Plugin
  • Microsoft Issues Urgent Update for Windows 11 Bugs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark