Fake MRI File Used to Deliver Iran Spyware

The Record · High sophistication
Last updated September 16, 2026

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan result, after initial contact on WhatsApp/Telegram while impersonating a known contact or technical support.

How the attack worked

This campaign relied on long-running social engineering rather than technical exploits alone. Operators made initial contact with targets over WhatsApp or Telegram, often posing as a known contact or as technical support. Instead of pushing a malicious file immediately, they spent time building rapport and trust with the target before delivering it. One lure that stands out was a file disguised as a fake MRI scan of a disk herniation, a highly personal and emotionally charged pretext designed to lower the target's guard. Other lures impersonated legitimate software products, including Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, so the malicious file matched whatever story the attacker was using.

Why it succeeded

The core reason this worked is trust. By the time the malicious file arrived, the target already believed they were talking to a known contact or a legitimate support agent. That rapport-building phase made the eventual file drop feel routine rather than suspicious. Tailoring the lure to something personal, like a medical scan, or something familiar, like a well-known app or antivirus tool, reduced the chance a target would pause and question the request. This approach targeted journalists, activists, and dissidents or opposition figures, groups who may already be dealing with high stress and urgency in their communications, making a convincing pretext even more effective.

What to watch for

  • Unexpected files sent through WhatsApp or Telegram, even from someone who appears to be a known contact
  • Messages claiming to be technical support that arrive through a personal chat app rather than an official company channel
  • Highly personal or urgent pretexts, such as medical results, sent as an attachment after a period of friendly conversation
  • Installer or update files for well-known software (antivirus, password managers, messaging apps) shared directly in chat instead of downloaded from an official source

Building resistance

Defenders and at-risk individuals should treat any unsolicited file sent over messaging apps as high risk, regardless of how familiar the sender seems, and verify the sender through a separate, known-good channel before opening anything. Real technical support should never deliver installers or fixes through chat apps. Because attackers may try to shift conversations to personal devices to bypass workplace protections, awareness guidance should extend beyond corporate systems. Once installed, this type of spyware can capture messages, screen activity, and audio, so the goal of training should be preventing the file from being opened in the first place, not just detecting it afterward.

Key findings

  • Spyware tool “CHOSEN BRICK” was delivered after “extensive social engineering campaigns to earn their trust.”
  • Attackers made “initial contact over messaging platforms such as WhatsApp and Telegram,” often impersonating “a known contact or as technical support,” then delivered a malicious file.
  • Lures were tailored to the target and included “a fake MRI scan of a disk herniation.”
  • Attackers also disguised malicious files as legitimate products (Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, KeePass).
  • The malware can steal contacts, email, and social messages, capture the screen, and turn on the microphone, enabling “pattern of life” tracking that can increase physical risk.
  • The campaign affected victims in the UK, US, and Netherlands and dates back to at least 2025; similar activity was linked by the FBI to actors operating on behalf of Iran’s MOIS.

Who’s being targeted

  • Commonly targeted roles: Security awareness program owners, Executives and high-risk individuals, Journalists / communications teams, Public affairs / policy staff, IT helpdesk (to counter impersonation narratives), All staff who use WhatsApp/Telegram for work-related communication.
  • Affected industries: Media (journalists), Non-profits / civil society (activists), Government-related / political (dissidents and opposition figures).
  • Attack channels: whatsapp, telegram.
  • Impersonated: Known contact (friend/colleague), Technical support.

Red flags to watch for

  • Unexpected medical/urgent attachment from a chat contact
  • File type doesn’t match what a real MRI provider would send (or comes without verification)
  • Pressure to open a file after rapport-building on messaging apps
  • Support contact initiated via WhatsApp/Telegram instead of official channels
  • Installer/update file shared directly in chat
  • Brand-name software offered from an unofficial source
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers deliver the spyware in this campaign?

Operators made initial contact over WhatsApp or Telegram, often posing as a known contact or technical support, built rapport with the target, and then sent a malicious file disguised as something innocuous, such as a fake MRI scan or legitimate software.

Who was targeted by this campaign?

Victims included journalists, activists, and dissidents or opposition figures in the UK, US, and Netherlands.

What can the spyware do once installed?

The malware can steal contacts, email, and social messages, capture the screen, and turn on the microphone, enabling pattern of life tracking that can increase physical risk to the target.

What legitimate products were impersonated in the attack?

Attackers disguised malicious files as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass.

Read the video transcript

Imagine a WhatsApp from a friend: “Here’s your MRI scan, looks like a disk herniation, open this file.” UK, US, and Dutch agencies say Iran-linked operators used that exact trick to drop spyware called CHOSEN BRICK, after weeks of chatting on WhatsApp or Telegram, posing as a friend or tech support. They’ve sent fake MRI scans and files pretending to be Norton, KeePass, Telegram, even Adobe Flash, shared directly in chat, not from any official site. Once opened, CHOSEN BRICK can read your email and messages, grab your contacts, record your screen, and turn on your mic. If you get any urgent MRI file or software installer over WhatsApp or Telegram, even from someone you trust, stop and call or message them on a separate, known-good channel to confirm before you open anything.

Similar attacks

Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Iran Uses WhatsApp Lures to Drop Chosen Brick Malware

Western government agencies warn that Iranian state-backed actors are using WhatsApp and Telegram messages to trick targeted individuals into installing a Windows surveillance and data-stealing tool called “Chosen Brick.” The attackers build trust by impersonating known people or organizations,…

September 15, 2026
Iranian Actors Lure Targets via Telegram/WhatsApp

Iranian Actors Lure Targets via Telegram/WhatsApp

UK, US, and Dutch authorities reported Iranian state-linked cyber actors using social messaging apps like Telegram and WhatsApp to build trust with dissidents, activists, and journalists. The actors then convince targets to open “legitimate-looking” files (fake apps or documents like MRI results)…

September 15, 2026
Iran-Linked Spyware Posed as Apps on WhatsApp

Iran-Linked Spyware Posed as Apps on WhatsApp

UK, US and Dutch authorities warned that Iran-linked attackers are targeting dissidents, activists, and journalists with Windows spyware. The group builds trust over messaging apps, then tricks victims into downloading malware disguised as legitimate software (or even medical files). The spyware…

September 15, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026