Security News

Iranian State Hackers Use Fake Medical Scans and Trusted Apps to Spy on Perceived Regime Critics

The Record · 16 Sept 2026
Key Takeaway Be cautious of unsolicited files or software update requests received via messaging apps, even from apparently known contacts, and verify identities through a separate channel before opening attachments.

Security agencies from Britain, the United States and the Netherlands have jointly issued a warning about spyware known as CHOSEN BRICK, used by Iranian state-sponsored hackers to target people the regime views as threats, including dissidents, activists and journalists. The malware has been delivered through carefully crafted lures, including a fake MRI scan, sent after lengthy social engineering campaigns designed to build trust with the victim.

According to the UK's National Cyber Security Centre, once installed, CHOSEN BRICK can harvest contacts, email inboxes and social media messages, capture screen content and even turn on a device's microphone. This information can be used to build a detailed picture of a victim's location, routine and relationships, increasing the risk of physical harm, with stolen details reportedly appearing on pro-Iranian leak sites to further intimidate targets.

The joint advisory, issued by the NCSC, the FBI and the Netherlands' AIVD, covers victims in all three countries dating back to at least 2025. Attackers typically make first contact through messaging apps like WhatsApp and Telegram, posing as known contacts or technical support, before sending malicious files disguised as legitimate software such as Norton Antivirus, Adobe Flash Player, KeePass or Telegram itself.

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.