Iranian Hackers Deploy CHOSEN BRICK Spyware via Fake MRI Results
Key Takeaways Iranian state-sponsored hackers are deploying CHOSEN BRICK spyware through highly personalized phishing attacks. Targets include dissidents, activists, and journalists in the UK, US,...
Key Takeaways
- Iranian state-sponsored hackers are deploying CHOSEN BRICK spyware through highly personalized phishing attacks.
- Targets include dissidents, activists, and journalists in the UK, US, and Netherlands, with campaigns active since at least 2025.
- The attackers build trust over WhatsApp or Telegram, often using fake MRI results or other urgent, tailored lures.
- CHOSEN BRICK is a Windows-specific spyware designed for long-term surveillance, capable of extensive data exfiltration, including personal communications and system information.
- Compromised personal data has been observed appearing on pro-Iranian leak sites, indicating the campaign’s intent for harassment and intimidation.
Sophisticated Social Engineering Delivers CHOSEN BRICK Spyware
A sophisticated cyberespionage campaign attributed to Iranian state-linked actors is leveraging highly personalized social engineering tactics, including fake MRI scan results, to compromise high-value targets with a Windows-based spyware family dubbed CHOSEN BRICK. This malware is engineered for persistent surveillance, enabling long-term data collection from infected systems.
Table Of Content
The campaign, which has been operational since at least 2025, primarily targets individuals in the United Kingdom, United States, and Netherlands. Specific targets include dissidents, human rights activists, and journalists, indicating a focused effort on intelligence gathering and harassment rather than broad financial exploitation.
The danger of this operation lies in its meticulous attention to individual victims and the attackers’ ability to maintain covert access and gather information long after the initial compromise. This sustained surveillance can reveal deeply personal details about a target’s life, contacts, and movements.
Initial Access and Persistence
Attackers initiate contact via messaging platforms like WhatsApp or Telegram, meticulously cultivating trust with their targets. They frequently impersonate known contacts or technical support personnel before delivering a malicious file disguised as a relevant document. For example, a common lure involves presenting a file as urgent MRI results, capitalizing on the psychological impact of health-related information to prompt immediate action. Other disguises include files appearing as legitimate applications. The attackers ensure that when the malicious file is opened, a convincing decoy screen is displayed, distracting the victim while the CHOSEN BRICK spyware silently installs in the background.
The UK National Cyber Security Centre (NCSC) has identified CHOSEN BRICK and issued warnings about its capabilities. The spyware can exfiltrate contacts, email correspondence, and social media messages, providing threat actors with a comprehensive overview of a victim’s relationships, geographical location, and daily routines. This data collection goes far beyond typical data theft, enabling detailed profiling and potential real-world repercussions.
According to a report shared with Cyber Security News (CSN), the NCSC noted that in some instances, personal information stolen from victims has subsequently appeared on pro-Iranian leak sites, underscoring the political motivations behind these attacks. The NCSC collaborated with the FBI and the Netherlands’ AIVD to release an advisory, linking the CHOSEN BRICK spyware to a broader pattern of state-sponsored cyber activities aimed at pressuring perceived opponents across borders.
Technical Modus Operandi
The effectiveness of the MRI lure stems from its ability to create a sense of urgency and personal relevance. While other lures mimic familiar applications, the attackers consistently tailor their narratives to each recipient. If initial attempts to compromise a work device are thwarted by corporate security measures, the attackers pivot, urging victims to open the malicious file on a personal device. This tactic circumvents enterprise safeguards and highlights the critical need for personal device security awareness. All observed CHOSEN BRICK infections have targeted Windows operating systems.
Upon successful execution, CHOSEN BRICK establishes persistence by adding an entry to the current user’s Run registry location (HKCUSoftwareMicrosoftWindowsCurrentVersionRun), ensuring it restarts automatically with each user login. It also attempts to add antivirus exclusions to evade detection. This technique mirrors other malware campaigns where deceptive software utilizes Windows startup settings to maintain unauthorized access.

The spyware employs a unique Telegram bot for each victim to facilitate command and control (C2) communications. Utilizing a legitimate online service like Telegram for C2 operations makes it challenging to distinguish malicious traffic from legitimate network activity. While NCSC has not observed automated lateral movement between compromised computers, the implant is capable of downloading additional malware payloads.
Surveillance Risks and Response
Once CHOSEN BRICK is active, it grants attackers extensive control over the compromised system. Capabilities include enumerating running processes and system details, capturing screenshots, recording audio, exfiltrating Telegram and WhatsApp browser data, stealing emails, executing arbitrary Windows commands, and deleting files. At least one variant of the spyware has been observed incorporating a data-wiping function. Exfiltrated data is typically sent to attackers via Telegram or cloud storage services, with proxy services often used to obfuscate the Telegram connection.
The ability to capture screenshots is particularly concerning in this campaign, as a single image can inadvertently expose a wealth of sensitive information, including contacts, ongoing work, travel plans, and private conversations. The NCSC has reported instances where information harvested from victims was subsequently published by the attackers, likely as a form of harassment or intimidation. This targeting model is reminiscent of other spyware campaigns, where seemingly innocuous files serve as decoys while sophisticated surveillance tools are installed.
What You Should Do
- Exercise Extreme Caution: Never install software or open attachments received through unexpected links or messages, even if the sender appears familiar. Verify the sender’s identity through an alternative, trusted communication channel.
- Download from Official Sources: Only obtain applications and software updates from official vendor websites or reputable app stores.
- Maintain Updated Systems: Keep your operating system, applications, and security software (antivirus/anti-malware) fully patched and up-to-date.
- Heed Security Warnings: Pay close attention to any warnings or alerts from your operating system or security software regarding file downloads or installations. Do not bypass them without understanding the implications.
- Educate Staff and Self: If you or your organization are potential targets (e.g., dissidents, activists, journalists), ensure staff are thoroughly briefed on these threats. Consider personal devices as potential targets and include them in organizational security awareness programs.
- Implement Strong Authentication: Use phishing-resistant multi-factor authentication (MFA) wherever possible.
- Enhance Security Controls: Organizations should deploy application allowlisting, robust email scanning, endpoint detection and response (EDR), and network monitoring solutions. Regularly search logs for the provided Indicators of Compromise (IoCs).
- Report and Preserve Evidence: If you suspect a compromise, immediately contact your internal IT department or an external cybersecurity provider. Preserve all relevant digital evidence for forensic analysis.
Indicators of Compromise (IoCs)
The following indicators have been identified in connection with CHOSEN BRICK activity. These should be integrated into threat intelligence platforms and security monitoring systems for detection and analysis.
| Type | Indicator | Description |
|---|---|---|
| Registry key | HKCUSoftwareMicrosoftWindowsCurrentVersionRun |
Run registry location used by CHOSEN BRICK for persistence at user logon |
| Registry value | SMQDService |
Previously observed malicious Run-key value name |
| File path | C:ProgramDataSMQDServicePackages...smdqservice.exe |
Value data associated with the SMQDService persistence entry |
| Registry value | winappx |
Previously observed malicious Run-key value name |
| File path | C:UsersAll UsersMicrosoftDistributionsysmainwinappx.exe |
Value data associated with the winappx persistence entry |
| Mutex | ytyjyujyu |
Commonly observed CHOSEN BRICK mutex |
| Mutex | noi672pp434awkc12f |
Commonly observed CHOSEN BRICK mutex |
| File path | C:Windows SysWOW64 |
Non-standard directory, including a space after Windows, used for additional payloads |
| Domain | api[.]telegram[.]org |
Telegram service domain that should be investigated when unexpected |
| Domain | backblazeb2[.]com |
Cloud-storage domain identified for investigation |
| Domain | vultrobjects[.]com |
Cloud object-storage domain identified for investigation |
| Domain | storjshare[.]io |
Cloud-storage domain identified for investigation |
| Domain | iproyal[.]com |
Proxy-service domain identified for investigation |
| Domain | lightningproxies[.]net |
Proxy-service domain identified for investigation |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.