Iran uses spyware disguised as MRI scan results to hack critics, say western officials

Iran has used spyware disguised as MRI scan results to collect information on dissidents, activists and journalists around the world, western intelligence agencies have warned.

The UK’s National Cyber Security Centre, America’s FBI and the Dutch intelligence and security service on Tuesday said they had uncovered a tool, dubbed Chosen Brick, being used by Iran to hack electronic devices including computers.

The malware allows attackers to collect a target’s contacts, emails and social media messages, while also providing access to the device’s microphone, the agencies said in a joint statement.

Personal details of victims targeted with Chosen Brick had already appeared on pro-Iranian leak websites, the agencies added, noting that Iran’s intelligence services had a record of plotting to kidnap or kill perceived enemies of the Islamic regime abroad.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said Paul Chichester, director of operations at the NCSC, part of the UK’s signals intelligence agency GCHQ.

Iran’s embassy in London did not immediately respond to a request for comment.

The western intelligence agencies said they were publicising details of the alleged Iranian campaign in order to warn potential targets.

The attackers tended to first engage with a target on social messaging platforms, such as WhatsApp and Telegram, having previously conducted extensive research on the person in order to present themselves as a “trusted” entity, the joint statement said.

Having built a rapport, the attackers then convinced the target to unknowingly download the spyware by clicking on a web link or downloading a file. In at least one case, the file appeared to be a set of MRI scan results, the statement added.

The FBI said the spyware had been deployed on behalf of Iran’s Ministry of Intelligence and Security since at least 2023.

“MOIS cyber actors likely use this malware to collect intelligence, conduct data leaks and inflict reputational harm,” it added.

Both the NCSC and FBI said the spyware exclusively targeted Microsoft Windows operating systems and remained on infected devices even after rebooting.

“The malware may change and the actors may change, but the approach is remarkably consistent: exploit trust, gain access, steal information,” said Gary Barlet at US cyber security company Illumio.

“The real takeaway from the NCSC is that organisations and individuals still underestimate how often they’re being targeted,” he added.

Additional reporting by Andrew England

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论