ZeroHour

Search: “attention”

380 stories

Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware

Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.

A joint advisory from the UK NCSC, FBI, and the Netherlands' AIVD links Iranian state-linked actors to CHOSEN BRICK, a Windows spyware family used for long-term surveillance since at least 2025. Targets are approached on WhatsApp or Telegram with tailored lures such as fake MRI scan results or application files, and operators often redirect victims to personal devices to bypass corporate controls. The malware persists via Run registry keys, adds antivirus exclusions, uses a per-victim Telegram bot for command and control, and exfiltrates data through cloud storage and proxy services. Capabilities include screenshots, audio recording, email and messaging theft, command execution, file deletion, data wiping, and some victims' details have appeared on pro-Iranian leak sites for harassment.

Cyber Security Newsupdated · 3h agofirst · 1d agoThreat actor in the wild 7 sources1

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

Researchers expose DPRK remote IT worker infiltration tactics, including forged identities and AI-assisted interview behavior.

A joint investigation by Mauro Eldritch, Heiner García, and ANY.RUN hired suspected DPRK developers linked to Lazarus Group into controlled sandboxes, revealing forged IDs, remote-access tools, AI-assisted workflows, and VPN/VPS infrastructure. The FBI is investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. The article outlines verification steps and indicators including VPS and AstrillVPN exit node IPs.

The Hacker News · Aug 15, 2026Threat actor in the wild