Full Report
British, American and Dutch security agencies issued a warning on Tuesday exposing a spyware tool being used by Iranian state-sponsored hackers to target individuals perceived as posing a threat to the regime. The malware, named CHOSEN BRICK by British intelligence, has been delivered using a range of lures — including a fake MRI scan of…
Analysis Summary
# Threat Actor: Iranian State-Sponsored Hackers
## Attribution & Identity
* **Actor Identification:** Iranian state-sponsored cyber spies.
* **Aliases:** While the specific group name (e.g., APT42, Charming Kitten) is not explicitly named in this short report, the malware they utilize is identified as **CHOSEN BRICK** by British intelligence.
* **Known Associations:** Linked to the Iranian government and regime security apparatus.
## Activity Summary
In September 2026, security agencies from the UK (NCSC), USA, and the Netherlands exposed a campaign involving the delivery of a new spyware tool. The operation involves sophisticated social engineering where attackers spend significant time building trust with their targets before delivering malicious payloads. Recent lures include highly personalized content, such as fake medical records (e.g., MRI scans for disk herniation).
## Tactics, Techniques & Procedures
* **Social Engineering:** Extensive campaigns designed to earn the trust of the victim before a payload is sent.
* **Phishing/Malicious Lures:** Delivery of spyware via deceptive documents, specifically a fake MRI scan of a disk herniation.
* **Spyware Deployment:** Use of bespoke tools to monitor and exfiltrate data from targeted individuals.
* **MITRE ATT&CK IDs:**
* T1566 (Phishing)
* T1204.002 (User Execution: Malicious File)
* T1583 (Develop Capabilities)
## Targeting
* **Sectors:** Civil Society, Journalism, Human Rights.
* **Geography:** Global (targeting the Iranian diaspora and international critics).
* **Victims:** Dissidents, activists, journalists, and individuals perceived as posing a threat to the Iranian regime.
## Tools & Infrastructure
* **Malware families used:** CHOSEN BRICK (Spyware).
* **Infrastructure:** The article notes the delivery of lures through social engineering; specific C2 domains and IP addresses were not listed in the provided text.
## Implications
This activity highlights the Iranian regime's continued reliance on cyber operations to project power beyond its borders and suppress domestic opposition. The shift toward high-effort social engineering and personalized medical lures indicates an evolution in tradecraft designed to bypass standard email security filters and exploit the human element of trust. It represents a significant threat to the physical and digital safety of Iranian dissidents worldwide.
## Mitigations
* **Vigilance against Social Engineering:** Exercise extreme caution when receiving unsolicited attachments or links, even from seemingly trusted contacts, especially if the communication follows a period of "grooming."
* **Verification of Medical Lures:** Verify the legitimacy of medical documents through official patient portals or via a secondary, known-good communication channel.
* **Endpoint Protection:** Deploy advanced endpoint detection and response (EDR) tools to identify and block the execution of unknown spyware variants like CHOSEN BRICK.
* **Multi-Factor Authentication (MFA):** Ensure all sensitive accounts for high-risk individuals are protected by hardware-based MFA to prevent credential compromise.