Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware

Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware

Posted on September 16, 2026 By CWS

Hackers affiliated with the Iranian state are leveraging counterfeit MRI scan results to deploy CHOSEN BRICK, a type of spyware targeting Windows systems for prolonged surveillance. This campaign, identified by national cybersecurity bodies, has been active in the UK, US, and Netherlands since 2025, primarily focusing on dissidents, activists, and journalists.

Targeted Surveillance Efforts

Unlike broad financial cyber attacks, this operation demonstrates a concentrated effort on espionage. The threat lies in the attackers’ ability to persistently gather data post-infection without drawing attention. Typically, the perpetrators initiate contact through platforms like WhatsApp or Telegram, impersonating trusted contacts or support personnel to build credibility.

Once trust is established, a deceptive file is sent, disguised as a relevant document to the recipient, similar to previous malware campaigns concealed as student resumes. The UK’s National Cyber Security Centre (NCSC) has identified this tactic as part of a broader pattern of cross-border intimidation against perceived adversaries.

Technical Tactics and Implications

The attackers exploit a sense of urgency with the MRI lure, making the scam appear personal. They adapt the narrative to suit individual targets, presenting a convincing front while the actual spyware installs silently. The malware specifically targets Windows devices, leveraging the Run registry for persistence and employing antivirus exclusions to avoid detection.

This malicious software communicates with dedicated Telegram bots for each victim, complicating the identification of harmful traffic amidst legitimate online activities. Although there is no evidence of automated propagation between systems, the spyware has capabilities to download additional malicious software if required.

Protective Measures and Recommendations

Once activated, CHOSEN BRICK can execute numerous invasive actions such as capturing screenshots, recording audio, and collecting communications data from platforms like Telegram and WhatsApp. In some cases, it includes data-wiping functionalities, escalating the potential damage from these breaches.

To mitigate risks, cybersecurity experts advise against opening unexpected attachments or links, even from seemingly familiar senders. Ensuring software is sourced from official channels, keeping devices updated, and adhering to security prompts can significantly reduce vulnerability to these attacks.

Organizations should educate employees on recognizing phishing attempts and include personal devices in their security protocols. Implementing robust security measures such as multi-factor authentication and comprehensive network monitoring can further safeguard against these threats.

Cyber Security News Tags:AIVD, CHOSEN BRICK, cyber attack, Cybersecurity, data breach, fake MRI, FBI, Iranian hackers, NCSC, online security, Phishing, Spyware, Surveillance, Telegram, WhatsApp

Post navigation

Previous Post: Acronis Urgently Fixes Vulnerability in cPanel Plugin

Related Posts

Critical Cisco Vulnerability Exposes SD-WAN to Attacks Critical Cisco Vulnerability Exposes SD-WAN to Attacks Cyber Security News
CISA Warns of Libraesva ESG Command Injection Vulnerability Actively Exploited in Attacks CISA Warns of Libraesva ESG Command Injection Vulnerability Actively Exploited in Attacks Cyber Security News
Android Packer Ducex Employs Serious Obfuscation Techniques and Detects Analysis Tools Presence Android Packer Ducex Employs Serious Obfuscation Techniques and Detects Analysis Tools Presence Cyber Security News
INE Security Expands Across Middle East and Asia to Accelerate Cybersecurity Upskillin INE Security Expands Across Middle East and Asia to Accelerate Cybersecurity Upskillin Cyber Security News
Bragg Confirms Cyber Attack – Hackers Accessed Internal IT Systems Bragg Confirms Cyber Attack – Hackers Accessed Internal IT Systems Cyber Security News
Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware
  • Acronis Urgently Fixes Vulnerability in cPanel Plugin
  • Microsoft Issues Urgent Update for Windows 11 Bugs
  • Critical WSO2 Flaw Exploited for Enterprise Data Breach
  • Critical WSO2 API Manager Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian Hackers Exploit Fake MRI Reports to Deliver Spyware
  • Acronis Urgently Fixes Vulnerability in cPanel Plugin
  • Microsoft Issues Urgent Update for Windows 11 Bugs
  • Critical WSO2 Flaw Exploited for Enterprise Data Breach
  • Critical WSO2 API Manager Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark