Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance.

The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, activists and journalists facing particular risk. The advisory describes a focused espionage effort rather than a broad financial crime campaign.

Its danger comes from the attention paid to each victim and from the operators’ ability to continue gathering information after the first deceptive file is opened without attracting attention.

The attackers begin conversations on WhatsApp or Telegram and spend time building trust. They may pose as a known contact or platform support worker, then send a file that looks relevant to the target, much like a fake student resume campaign hides malware behind an expected document.

Analysts at the UK National Cyber Security Centre, or NCSC, identified CHOSEN BRICK and warned that it can collect contacts, email and social-media messages.

That material can reveal a person’s relationships, location and daily routine, raising the stakes beyond ordinary data theft.

NCSC said in a report shared with Cyber Security News (CSN) that victims’ personal details have, in some cases, appeared on pro-Iranian leak sites.

The agency issued the advisory with the FBI and the Netherlands’ AIVD, connecting the spyware to a wider pattern of cross-border pressure on perceived opponents.

Iranian Hackers Use Fake MRI Results

The MRI lure works because it creates urgency and looks personal. Other observed disguises include files presented as familiar applications, but the actors tailor the story to each recipient and display a convincing screen once the file is opened, while the real installation continues out of sight.

Operators often first contact a work device. If company controls prevent the delivery or increase the chance of discovery, they ask the person to open the same file on a personal device instead.

That shift can sidestep safeguards maintained by an employer and makes personal-device awareness essential. Every observed CHOSEN BRICK infection targeted Windows.

After launch, the malware uses the current user’s Run registry location so it starts again at login, then adds antivirus exclusions to reduce detection.

This familiar approach resembles signed malware masquerading apps, where deceptive software also used Windows startup settings to retain access.

Lure file (Source – NCSC)

The spyware communicates with a distinct Telegram bot for each victim. Using a legitimate online service as a control channel can make malicious traffic harder to separate from everyday activity, a pattern also covered in Telegram based remote access.

NCSC said it has not seen automated movement between computers, though the implant can download further malware.

Surveillance Risks and Response

Once active, CHOSEN BRICK can inspect running programs and system details, take screenshots, record audio, collect Telegram and WhatsApp browser data, steal emails, run Windows commands, and delete files.

In at least one sample, it included a data-wiping function. Stolen information may leave through Telegram or cloud storage services, while proxy services can conceal the Telegram connection.

Screen captures are especially sensitive in this campaign because they can expose contacts, work, travel and private conversations in one image.

NCSC said actors have sometimes published information taken from victims to harass them. That targeting model echoes a fake PDF spyware campaign, in which a harmless-looking file opens a decoy while surveillance software installs.

People should not install software received through an unexpected attachment or link, even when a sender seems familiar.

They should obtain applications only through official sources, keep devices and security software updated, and heed Windows file-download warnings instead of bypassing them. These simple checks matter when an attacker has prepared a convincing personal story.

Organizations should brief staff who may be targeted and include personal devices in their support process. Administrators should use phishing-resistant multi-factor authentication, application allowlisting, email scanning, endpoint and network monitoring, and searches across logs for the indicators below.

Anyone who suspects execution should contact their internal or external IT provider promptly and preserve relevant evidence.

Indicators of compromise (IoCs):-

Type Indicator Description
Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run Run registry location used by CHOSEN BRICK for persistence at user logon
Registry value SMQDService Previously observed malicious Run-key value name
File path C:\ProgramData\SMQDServicePackages\...\smdqservice.exe Value data associated with the SMQDService persistence entry
Registry value winappx Previously observed malicious Run-key value name
File path C:\Users\All Users\MicrosoftDistribution\sysmain\winappx.exe Value data associated with the winappx persistence entry
Mutex ytyjyujyu Commonly observed CHOSEN BRICK mutex
Mutex noi672pp434awkc12f Commonly observed CHOSEN BRICK mutex
File path C:\Windows \SysWOW64 Non-standard directory, including a space after Windows, used for additional payloads
Domain api[.]telegram[.]org Telegram service domain that should be investigated when unexpected
Domain backblazeb2[.]com Cloud-storage domain identified for investigation
Domain vultrobjects[.]com Cloud object-storage domain identified for investigation
Domain storjshare[.]io Cloud-storage domain identified for investigation
Domain iproyal[.]com Proxy-service domain identified for investigation
Domain lightningproxies[.]net Proxy-service domain identified for investigation

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.