Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.
A joint advisory from the UK NCSC, FBI, and the Netherlands' AIVD links Iranian state-linked actors to CHOSEN BRICK, a Windows spyware family used for long-term surveillance since at least 2025. Targets are approached on WhatsApp or Telegram with tailored lures such as fake MRI scan results or application files, and operators often redirect victims to personal devices to bypass corporate controls. The malware persists via Run registry keys, adds antivirus exclusions, uses a per-victim Telegram bot for command and control, and exfiltrates data through cloud storage and proxy services. Capabilities include screenshots, audio recording, email and messaging theft, command execution, file deletion, data wiping, and some victims' details have appeared on pro-Iranian leak sites for harassment.
- NCSC, FBI, and AIVD jointly tied CHOSEN BRICK to Iranian state-linked espionage
- Victims are contacted on WhatsApp or Telegram and sent fake MRI results or app files
- Malware persists via Run registry keys and adds antivirus exclusions to evade detection
- Per-victim Telegram bots provide C2; data leaves via cloud storage and proxy services
- Capabilities include screenshots, audio recording, message theft, command execution, and data wiping
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | api.telegram.org | a space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated whe |
| domain | backblazeb2.com | e domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation Domain |
| domain | iproyal.com | io Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation Domain |
| domain | lightningproxies.net | om Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: I |
| domain | storjshare.io | d object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation Domain |
| domain | vultrobjects.com | om Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigation |
Full article905 words · extracted from cybersecuritynews.com · click to collapse
Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance.
The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, activists and journalists facing particular risk. The advisory describes a focused espionage effort rather than a broad financial crime campaign.
Its danger comes from the attention paid to each victim and from the operators’ ability to continue gathering information after the first deceptive file is opened without attracting attention.
The attackers begin conversations on WhatsApp or Telegram and spend time building trust. They may pose as a known contact or platform support worker, then send a file that looks relevant to the target, much like a fake student resume campaign hides malware behind an expected document.
Analysts at the UK National Cyber Security Centre, or NCSC, identified CHOSEN BRICK and warned that it can collect contacts, email and social-media messages.
That material can reveal a person’s relationships, location and daily routine, raising the stakes beyond ordinary data theft.
NCSC said in a report shared with Cyber Security News (CSN) that victims’ personal details have, in some cases, appeared on pro-Iranian leak sites.
The agency issued the advisory with the FBI and the Netherlands’ AIVD, connecting the spyware to a wider pattern of cross-border pressure on perceived opponents.
Iranian Hackers Use Fake MRI Results
The MRI lure works because it creates urgency and looks personal. Other observed disguises include files presented as familiar applications, but the actors tailor the story to each recipient and display a convincing screen once the file is opened, while the real installation continues out of sight.
Operators often first contact a work device. If company controls prevent the delivery or increase the chance of discovery, they ask the person to open the same file on a personal device instead.
That shift can sidestep safeguards maintained by an employer and makes personal-device awareness essential. Every observed CHOSEN BRICK infection targeted Windows.
After launch, the malware uses the current user’s Run registry location so it starts again at login, then adds antivirus exclusions to reduce detection.
This familiar approach resembles signed malware masquerading apps, where deceptive software also used Windows startup settings to retain access.
.webp)
The spyware communicates with a distinct Telegram bot for each victim. Using a legitimate online service as a control channel can make malicious traffic harder to separate from everyday activity, a pattern also covered in Telegram based remote access.
NCSC said it has not seen automated movement between computers, though the implant can download further malware.
Surveillance Risks and Response
Once active, CHOSEN BRICK can inspect running programs and system details, take screenshots, record audio, collect Telegram and WhatsApp browser data, steal emails, run Windows commands, and delete files.
In at least one sample, it included a data-wiping function. Stolen information may leave through Telegram or cloud storage services, while proxy services can conceal the Telegram connection.
Screen captures are especially sensitive in this campaign because they can expose contacts, work, travel and private conversations in one image.
NCSC said actors have sometimes published information taken from victims to harass them. That targeting model echoes a fake PDF spyware campaign, in which a harmless-looking file opens a decoy while surveillance software installs.
People should not install software received through an unexpected attachment or link, even when a sender seems familiar.
They should obtain applications only through official sources, keep devices and security software updated, and heed Windows file-download warnings instead of bypassing them. These simple checks matter when an attacker has prepared a convincing personal story.
Organizations should brief staff who may be targeted and include personal devices in their support process. Administrators should use phishing-resistant multi-factor authentication, application allowlisting, email scanning, endpoint and network monitoring, and searches across logs for the indicators below.
Anyone who suspects execution should contact their internal or external IT provider promptly and preserve relevant evidence.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Registry key | HKCU\Software\Microsoft\Windows\CurrentVersion\Run | Run registry location used by CHOSEN BRICK for persistence at user logon |
| Registry value | SMQDService | Previously observed malicious Run-key value name |
| File path | C:\ProgramData\SMQDServicePackages\...\smdqservice.exe | Value data associated with the SMQDService persistence entry |
| Registry value | winappx | Previously observed malicious Run-key value name |
| File path | C:\Users\All Users\MicrosoftDistribution\sysmain\winappx.exe | Value data associated with the winappx persistence entry |
| Mutex | ytyjyujyu | Commonly observed CHOSEN BRICK mutex |
| Mutex | noi672pp434awkc12f | Commonly observed CHOSEN BRICK mutex |
| File path | C:\Windows \SysWOW64 | Non-standard directory, including a space after Windows, used for additional payloads |
| Domain | api[.]telegram[.]org | Telegram service domain that should be investigated when unexpected |
| Domain | backblazeb2[.]com | Cloud-storage domain identified for investigation |
| Domain | vultrobjects[.]com | Cloud object-storage domain identified for investigation |
| Domain | storjshare[.]io | Cloud-storage domain identified for investigation |
| Domain | iproyal[.]com | Proxy-service domain identified for investigation |
| Domain | lightningproxies[.]net | Proxy-service domain identified for investigation |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fake-mri-results/