Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results

September 16, 2026

Iranian state-affiliated cyber actors have adopted a sophisticated approach to target dissidents, activists, and journalists through the deployment of fake AI applications, counterfeit antivirus tools, and even fabricated MRI scan results. This campaign revolves around the distribution of CHOSEN BRICK, a spyware family specifically designed for Windows systems.

A recent advisory issued by the UK National Cyber Security Centre (NCSC), in collaboration with the FBI and the Netherlands’ AIVD, highlights that this campaign has been active since at least 2025, affecting individuals across the globe, including those in the UK, US, and Netherlands.

What sets this malware apart is not just its surveillance capabilities but also the broader operational context in which it operates. Authorities have assessed that Iranian cyber activities are being leveraged to suppress individuals deemed as threats to the regime. In some instances, Iranian intelligence services have reportedly pursued extreme measures, such as kidnappings or lethal operations against targets abroad, transforming the compromise of personal devices into a significant physical safety concern rather than merely a data security issue.

The tactics employed by these cyber actors include impersonating known contacts or posing as technical support staff from popular messaging services. Their social-engineering strategies are meticulously tailored based on detailed research of their targets, making the malicious files appear relevant and credible. Notable impersonations have included legitimate software like Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. In some cases, attackers have even sent files disguised as MRI scan results, referencing specific medical conditions to enhance their credibility.

Typically, the attackers initiate contact through a work or corporate device. If corporate security measures hinder execution or detection risks are too high, they shift the conversation to the victim’s personal device. This tactic is designed to circumvent enterprise endpoint protection, application-control policies, and centralized monitoring systems.

Once the malicious file is opened, it presents a convincing decoy screen that aligns with its theme, while secretly downloading and executing the core CHOSEN BRICK component. All known instances of this malware have exclusively targeted Windows systems.

CHOSEN BRICK Malware

CHOSEN BRICK establishes persistence through the Windows Registry Run key:

HKCUSoftwareMicrosoftWindowsCurrentVersionRun

This mechanism allows the malware to launch automatically when the user logs in, without requiring administrative privileges. Additionally, the malware attempts to add exclusions to Microsoft Defender, thereby reducing the chances of detection or removal.

Lure files (Source: NCSC).

For command-and-control operations, CHOSEN BRICK communicates via Telegram. Each victim is assigned a unique Telegram Bot ID, a strategic measure to limit overlap between compromised hosts and complicate both attribution and bulk detection. Recent samples have also utilized HTTPS and SOCKS5 proxies to obscure Telegram-related traffic.

The spyware is capable of downloading additional payloads and ensuring their persistence. While investigators have yet to observe automated lateral movement, the modular download capability provides operators with the flexibility to extend their activities beyond the initial infection.

CHOSEN BRICK supports extensive data collection and destructive actions. Operators can enumerate processes and system information, capture screenshots, record audio through the microphone, steal email content, and collect data from Telegram and WhatsApp browsers. Screenshots, in particular, are invaluable for intelligence gathering, as they can reveal contacts, conversations, schedules, locations, and behavioral patterns.

The advisory notes that personal information from some victims has surfaced on pro-Iranian leak sites, potentially heightening harassment and personal safety risks. Stolen data may be exfiltrated through Telegram bots or cloud storage services, including VultrObjects and StorjShare.

Organizations supporting high-risk personnel should extend their detection and response capabilities beyond managed corporate endpoints. The campaign’s deliberate shift to personal devices necessitates that security teams provide targeted awareness guidance and assistance to staff, journalists, activists, and other individuals likely to be targeted.

Administrators are advised to monitor for suspicious Registry Run-key entries, unexpected Defender exclusions, Telegram-linked communications, and anomalous executables stored in unusual directories. One observed payload location was C:WindowsSysWOW64, where a deliberate space after “Windows” creates a nonstandard directory path designed to blend in with legitimate Windows file-system activity.

Users are encouraged to refrain from installing software delivered through unsolicited attachments or messaging links, obtain applications solely from official vendor sites or trusted app stores, keep Windows and security software updated, and treat SmartScreen warnings as critical signals rather than mere inconveniences.

The FBI tracks the same malware family under the name HEAVYGRAM, expanding the lexicon of terms that defenders should incorporate into their threat-hunting and intelligence workflows.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Tech Optimizer
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results