Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Iranian Hackers Use Fake Apps and Medical Scans to Spread CHOSEN BRICK Spyware

Iranian Hackers Use Fake Apps and Medical Scans to Spread CHOSEN BRICK Spyware

By: Jordan Vector — Cybersecurity Expert

Last updated: September 17, 2026

Human Written
Iranian Hackers Use Fake Apps and Medical Scans to Spread CHOSEN BRICK Spyware
  • Iranian hackers hide a spy tool called CHOSEN BRICK inside fake apps and fake medical scans.

  • The malware can watch your screen, turn on your microphone, and steal your messages.

  • The UK, US, and Netherlands shared a joint warning about the threat on September 15, 2026.

Trusted apps and everyday chat messages are turning into weapons for state-backed spies. Iranian hackers now send fake software and fake documents to trick people into opening dangerous files. Once a target clicks, a spy tool takes over their computer without warning.

According to a joint advisory from the UK’s National Cyber Security Centre (NCSC), the FBI, and the Netherlands’ AIVD, this campaign has targeted dissidents, activists, and journalists since at least 2025.

Fake Apps and Trusted Contacts Open the Door

The attack starts with a friendly message, not a broken link or a scary warning. Hackers reach out on WhatsApp or Telegram. They act like someone the target already knows. Sometimes they pretend to be tech support instead.

The hackers spend time building trust before they make a move. They learn about a person’s life first. Then they use those details to sound believable and real.

Once trust is built, the hacker sends a file. The file looks like a normal app or document. Past lures have copied Telegram, KeePass, Norton Antivirus, and Adobe Flash Player. Fake versions of Pictory and RunwayML have also shown up, according to the NCSC’s technical report. In one case, attackers even sent a fake MRI scan result.

When a person opens the file, it looks just like the real thing. But behind that screen, a spy tool called CHOSEN BRICK quietly installs itself. The FBI tracks the same malware family under a different name, HEAVYGRAM.

This tool only attacks Windows computers, not phones or Macs. Hackers often try a work laptop first. If security software blocks them there, they push the target to open the file on a personal device instead.

The Spyware Watches, Listens, and Steals

Once CHOSEN BRICK gets in, it does not leave easily. It adds itself to the Windows startup list. That way, it turns back on every time the computer restarts. The malware also tricks Microsoft Defender. It adds itself to a list of safe files. This helps it hide from normal antivirus scans.

CHOSEN BRICK talks to its hackers through Telegram bots. This makes its traffic blend in with normal chat app activity. That helps it avoid raising alarms on a network.

The spy tool can do a lot of damage. It can take screenshots of a victim’s screen at any time. It can turn on the microphone and record nearby sounds. Also read Telegram and WhatsApp messages saved in a browser.

Email content is not safe either. The malware can grab it directly. In some cases, it can even delete files or wipe a computer completely, according to the joint advisory.

Screenshots alone can reveal a lot about someone’s life. They can show a person’s contacts, daily habits, and even their location. Stolen data from past victims has shown up on pro-Iranian leak sites. This raises real safety risks for the people targeted.

The scale of Iranian cyber activity extends beyond individual spyware campaigns. US authorities have also offered a $10 million reward for information about Iranian hackers linked to the theft of 31.5TB of data, highlighting the broader reach of these operations.

Agencies Share Ways to Stay Protected

The NCSC, FBI, and AIVD are urging people to take a few simple steps. Do not install software sent through a chat message or email attachment. Only download apps from official stores or trusted company websites.

Keep your operating system and apps updated at all times. Old software often has holes that hackers can slip through. Updates close those gaps and lower your risk.

Running antivirus software helps, but only if it stays active and updated. Do not turn it off, even for a short time. Also, pay attention to Microsoft SmartScreen warnings. Do not click past them without checking first.

Businesses have extra steps they can take too. Agencies recommend phishing-resistant multi-factor authentication for logins. Strong app controls and endpoint monitoring also help spot trouble early. Watching network logs closely can catch strange activity fast.

The NCSC, FBI, and AIVD say this advisory is meant to help people spot the threat. Knowing how the attack works is the first step. Reporting suspicious messages early can also stop an attack in its tracks.

Nobody expects a spy tool to arrive wrapped in a friendly chat message. That is exactly why this attack has worked for so long. Stay cautious about unexpected files, even from people you trust. A quick double-check now could save your personal data later.

Share this article

You might also like

US Charges Five Alleged Black Axe Leaders After Extradition from South Africa

US Charges Five Alleged Black Axe Leaders After Extradition from South Africa

Five men who are supposedly Black Axe leaders are now awaiting trials in the U.S. after an extended extradition battle.…

September 17, 2026
KREMLIN Banking Malware Targets Brazilian Users with Malicious Browser Extension

KREMLIN Banking Malware Targets Brazilian Users with Malicious Browser Extension

KREMLIN has targeted Brazilian bank customers in seven separate attacks since at least May 2025. The malware sneaks in a…

September 17, 2026
Paris Man Accused of Hacking Police and Court Systems to Defraud Notaries

Paris Man Accused of Hacking French Police and Justice Servers in €1 Million Fraud Scheme

A 25-year-old man in Paris allegedly hacked police and court computer systems to launch a scam. He posed as police…

September 15, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.