Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Parallels Desktop Vulnerability Lets Non-Admin Mac Users Execute Code as Root
September 16, 2026
Critical Acronis Cyber Protection Vulnerability in cPanel, Plesk Exploosed
September 16, 2026
KREMLIN Banking Malware Spreads via Malicious Chrome Extension
September 16, 2026
Home/CyberSecurity News/Iranian Hackers Deploy CHOSEN BRICK Spyware via Fake MRI Results
CyberSecurity News

Iranian Hackers Deploy CHOSEN BRICK Spyware via Fake MRI Results

Key Takeaways Iranian state-sponsored hackers are deploying CHOSEN BRICK spyware through highly personalized phishing attacks. Targets include dissidents, activists, and journalists in the UK, US,...

Sarah simpson
Sarah simpson
September 16, 2026 5 Min Read
3 0

Key Takeaways

  • Iranian state-sponsored hackers are deploying CHOSEN BRICK spyware through highly personalized phishing attacks.
  • Targets include dissidents, activists, and journalists in the UK, US, and Netherlands, with campaigns active since at least 2025.
  • The attackers build trust over WhatsApp or Telegram, often using fake MRI results or other urgent, tailored lures.
  • CHOSEN BRICK is a Windows-specific spyware designed for long-term surveillance, capable of extensive data exfiltration, including personal communications and system information.
  • Compromised personal data has been observed appearing on pro-Iranian leak sites, indicating the campaign’s intent for harassment and intimidation.

Sophisticated Social Engineering Delivers CHOSEN BRICK Spyware

A sophisticated cyberespionage campaign attributed to Iranian state-linked actors is leveraging highly personalized social engineering tactics, including fake MRI scan results, to compromise high-value targets with a Windows-based spyware family dubbed CHOSEN BRICK. This malware is engineered for persistent surveillance, enabling long-term data collection from infected systems.

Table Of Content

  • Key Takeaways
  • Sophisticated Social Engineering Delivers CHOSEN BRICK Spyware
  • Initial Access and Persistence
  • Technical Modus Operandi
  • Surveillance Risks and Response
  • What You Should Do
  • Indicators of Compromise (IoCs)

The campaign, which has been operational since at least 2025, primarily targets individuals in the United Kingdom, United States, and Netherlands. Specific targets include dissidents, human rights activists, and journalists, indicating a focused effort on intelligence gathering and harassment rather than broad financial exploitation.

The danger of this operation lies in its meticulous attention to individual victims and the attackers’ ability to maintain covert access and gather information long after the initial compromise. This sustained surveillance can reveal deeply personal details about a target’s life, contacts, and movements.

Initial Access and Persistence

Attackers initiate contact via messaging platforms like WhatsApp or Telegram, meticulously cultivating trust with their targets. They frequently impersonate known contacts or technical support personnel before delivering a malicious file disguised as a relevant document. For example, a common lure involves presenting a file as urgent MRI results, capitalizing on the psychological impact of health-related information to prompt immediate action. Other disguises include files appearing as legitimate applications. The attackers ensure that when the malicious file is opened, a convincing decoy screen is displayed, distracting the victim while the CHOSEN BRICK spyware silently installs in the background.

The UK National Cyber Security Centre (NCSC) has identified CHOSEN BRICK and issued warnings about its capabilities. The spyware can exfiltrate contacts, email correspondence, and social media messages, providing threat actors with a comprehensive overview of a victim’s relationships, geographical location, and daily routines. This data collection goes far beyond typical data theft, enabling detailed profiling and potential real-world repercussions.

According to a report shared with Cyber Security News (CSN), the NCSC noted that in some instances, personal information stolen from victims has subsequently appeared on pro-Iranian leak sites, underscoring the political motivations behind these attacks. The NCSC collaborated with the FBI and the Netherlands’ AIVD to release an advisory, linking the CHOSEN BRICK spyware to a broader pattern of state-sponsored cyber activities aimed at pressuring perceived opponents across borders.

Technical Modus Operandi

The effectiveness of the MRI lure stems from its ability to create a sense of urgency and personal relevance. While other lures mimic familiar applications, the attackers consistently tailor their narratives to each recipient. If initial attempts to compromise a work device are thwarted by corporate security measures, the attackers pivot, urging victims to open the malicious file on a personal device. This tactic circumvents enterprise safeguards and highlights the critical need for personal device security awareness. All observed CHOSEN BRICK infections have targeted Windows operating systems.

Upon successful execution, CHOSEN BRICK establishes persistence by adding an entry to the current user’s Run registry location (HKCUSoftwareMicrosoftWindowsCurrentVersionRun), ensuring it restarts automatically with each user login. It also attempts to add antivirus exclusions to evade detection. This technique mirrors other malware campaigns where deceptive software utilizes Windows startup settings to maintain unauthorized access.

Lure file (Source - NCSC)
Lure file (Source – NCSC)

The spyware employs a unique Telegram bot for each victim to facilitate command and control (C2) communications. Utilizing a legitimate online service like Telegram for C2 operations makes it challenging to distinguish malicious traffic from legitimate network activity. While NCSC has not observed automated lateral movement between compromised computers, the implant is capable of downloading additional malware payloads.

Surveillance Risks and Response

Once CHOSEN BRICK is active, it grants attackers extensive control over the compromised system. Capabilities include enumerating running processes and system details, capturing screenshots, recording audio, exfiltrating Telegram and WhatsApp browser data, stealing emails, executing arbitrary Windows commands, and deleting files. At least one variant of the spyware has been observed incorporating a data-wiping function. Exfiltrated data is typically sent to attackers via Telegram or cloud storage services, with proxy services often used to obfuscate the Telegram connection.

The ability to capture screenshots is particularly concerning in this campaign, as a single image can inadvertently expose a wealth of sensitive information, including contacts, ongoing work, travel plans, and private conversations. The NCSC has reported instances where information harvested from victims was subsequently published by the attackers, likely as a form of harassment or intimidation. This targeting model is reminiscent of other spyware campaigns, where seemingly innocuous files serve as decoys while sophisticated surveillance tools are installed.

What You Should Do

  • Exercise Extreme Caution: Never install software or open attachments received through unexpected links or messages, even if the sender appears familiar. Verify the sender’s identity through an alternative, trusted communication channel.
  • Download from Official Sources: Only obtain applications and software updates from official vendor websites or reputable app stores.
  • Maintain Updated Systems: Keep your operating system, applications, and security software (antivirus/anti-malware) fully patched and up-to-date.
  • Heed Security Warnings: Pay close attention to any warnings or alerts from your operating system or security software regarding file downloads or installations. Do not bypass them without understanding the implications.
  • Educate Staff and Self: If you or your organization are potential targets (e.g., dissidents, activists, journalists), ensure staff are thoroughly briefed on these threats. Consider personal devices as potential targets and include them in organizational security awareness programs.
  • Implement Strong Authentication: Use phishing-resistant multi-factor authentication (MFA) wherever possible.
  • Enhance Security Controls: Organizations should deploy application allowlisting, robust email scanning, endpoint detection and response (EDR), and network monitoring solutions. Regularly search logs for the provided Indicators of Compromise (IoCs).
  • Report and Preserve Evidence: If you suspect a compromise, immediately contact your internal IT department or an external cybersecurity provider. Preserve all relevant digital evidence for forensic analysis.

Indicators of Compromise (IoCs)

The following indicators have been identified in connection with CHOSEN BRICK activity. These should be integrated into threat intelligence platforms and security monitoring systems for detection and analysis.

Type Indicator Description
Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun Run registry location used by CHOSEN BRICK for persistence at user logon
Registry value SMQDService Previously observed malicious Run-key value name
File path C:ProgramDataSMQDServicePackages...smdqservice.exe Value data associated with the SMQDService persistence entry
Registry value winappx Previously observed malicious Run-key value name
File path C:UsersAll UsersMicrosoftDistributionsysmainwinappx.exe Value data associated with the winappx persistence entry
Mutex ytyjyujyu Commonly observed CHOSEN BRICK mutex
Mutex noi672pp434awkc12f Commonly observed CHOSEN BRICK mutex
File path C:Windows SysWOW64 Non-standard directory, including a space after Windows, used for additional payloads
Domain api[.]telegram[.]org Telegram service domain that should be investigated when unexpected
Domain backblazeb2[.]com Cloud-storage domain identified for investigation
Domain vultrobjects[.]com Cloud object-storage domain identified for investigation
Domain storjshare[.]io Cloud-storage domain identified for investigation
Domain iproyal[.]com Proxy-service domain identified for investigation
Domain lightningproxies[.]net Proxy-service domain identified for investigation

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Apache Superset SQL Injection Vulnerability Gets Public PoC

Next Post

KREMLIN Banking Malware Spreads via Malicious Chrome Extension

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best SaaS Security Posture Management (SSPM) Tools
September 16, 2026
Top 10 Cloud Detection and Response Solutions for 2026
September 16, 2026
Microsoft Patches Critical Windows 11 Vulnerability CVE-2023-XXXXX
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us