The fake MRI results were the bait. CHOSEN BRICK was what came after
Three intelligence services just described, step by step, how someone you think you know on WhatsApp ends up switching on your microphone.
Someone you've spoken to before messages you on WhatsApp or Telegram. You chat for a while. Then comes a file — in at least one case, a set of MRI test results. Open it, and software lands on your computer that can read your contacts, your emails, your social media messages, watch your screen and turn on your microphone.
That software has a name now: CHOSEN BRICK. On 15 September 2026 the UK's National Cyber Security Centre — part of GCHQ — published a joint advisory with the US Federal Bureau of Investigation and the Netherlands' intelligence and security service, AIVD, describing it as spyware used by Iranian state actors against dissidents, activists and journalists around the world, including in the UK.
The important part isn't the malware. It's the method. The NCSC says the attackers impersonate contacts over messaging apps, build rapport first, and only then deploy CHOSEN BRICK — tailoring the lure to whatever the target actually cares about. The fake medical test results are the detail that should stop you: nobody ignores a message about their own health results. That is not a technical exploit. It is patience plus homework, and it works on anyone with a phone and a reason to open a file.
Trust is the vulnerability. The software is just the delivery.
Two details make this worse than a normal hack. First, the NCSC says CHOSEN BRICK is persistent and survives a reboot — turning the machine off and on again doesn't clear it. Second, what's taken doesn't stay private: personal details of some previous victims have appeared on pro-Iranian leak sites, which the NCSC says potentially increases the risk to their personal safety. So the chain runs from a friendly message to a published list of who you are and who you talk to.
One piece of good news, and it's narrow: the malware has been targeted exclusively at Windows. That limits the blast radius, and it tells you where the attackers expect their targets to keep their real work — documents, email, archives — rather than on a phone.
Most obviously, journalists, activists and dissidents who criticise the Iranian regime — the NCSC assesses Iran almost certainly uses cyber activity to support repression of people it sees as a threat. But look at the technique and the circle widens fast. Anyone who takes work through Telegram or WhatsApp — a freelance designer, a junior reporter, a student running a campus campaign, someone chasing a first crypto gig from a stranger who seems to know their world — is being approached the same way: a familiar name, a warm conversation, then one file. And anyone whose contacts list includes someone at risk is part of the harvest, because contacts, emails and messages are exactly what CHOSEN BRICK collects.
The FBI has published further technical analysis of the malware in a report released the same day, and the NCSC advisory carries the mitigation steps plus its own support for high-risk individuals, including free cyber defence services to sign up for. Beyond that, nobody named a deadline: no arrests, no attribution hearing, no review date appears in the announcement. The NCSC says only that it will continue to call out malicious cyber activity by the Iranian state.
Fake MRI results. Someone sat down and worked out that the one message a person will always open is the one about their own body. Every warning about suspicious links assumes the bait will look suspicious. This one was designed to look like the most normal message of your week.
Sources: UK National Cyber Security Centre (NCSC, part of GCHQ), news release and joint advisory with the FBI and the Netherlands' AIVD, 15 September 2026; FBI technical report published the same day.
Разведки трёх стран назвали конкретный иранский шпионский софт, который подсаживают через WhatsApp и Telegram — с перепиской, скриншотами и включением микрофона, а личные данные жертв потом всплывают на сливных сайтах, так что описанные приёмы (знакомый контакт, «результаты МРТ») работают против любого пользователя, не только против активистов.
Written by THE TELL’s AI newsroom. how we work · corrections