Das britische NCSC und das FBI haben eine iranische Spionagekampagne enttarnt, bei der Dissidenten und Journalisten mit gefälschten MRT-Scans geködert und mit der Spyware CHOSEN BRICK infiziert wurden.
In a coordinated threat advisory, the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Dutch General Intelligence and Security Service (AIVD) have uncovered an aggressive cyber espionage campaign operated by Iranian intelligence services. The campaign explicitly targets individuals perceived as adversaries of the Tehran regime—including exiled political dissidents, human rights defenders, investigative journalists, and academics across Europe and North America.
The intelligence agencies revealed that the Iranian threat actors invest significant time in bespoke social engineering across encrypted chat platforms like Telegram and WhatsApp. Posing as sympathetic peers, researchers, or medical contacts, the operatives establish rapport before sending weaponized lures. In one documented attack vector, operators transmitted links to a fake medical diagnostic MRI scan purportedly depicting spinal disc herniation. Downloading and executing the archive infected Windows endpoints with a novel, purpose-built surveillance implant named CHOSEN BRICK.
CHOSEN BRICK is an advanced Windows-based modular spyware suite. Once resident, it systematically harvests address books, local browser sessions, and Telegram message stores. Critically, it features surveillance capabilities enabling silent ambient microphone recording, periodic desktop screenshot capture, and clipboard logging. The harvested intelligence is encrypted and exfiltrated to adversary-controlled Command-and-Control (C2) nodes.
Security agencies warned that Iranian intelligence utilizes this data beyond digital espionage, leveraging exfiltrated physical coordinates and travel itineraries to coordinate real-world intimidation, harassment, and targeted kidnapping plots against dissidents abroad. The campaign exemplifies how state-backed offensive cyber operations are weaponized against human rights and democratic freedoms.
Guidance for High-Risk Individuals and Civil Society
- Zero-Trust for Direct Message Attachments: Never open executable files, compressed archives (`.zip`, `.rar`), or office documents received via messaging applications, regardless of sender familiarity.
- Inspect Documents in Air-Gapped or Sandboxed Viewers: Utilize web-based cloud previews (e.g., Google Docs viewer) rather than downloading native files to personal workstations.
- Deploy Hardware-Backed Multi-Factor Authentication: Secure communication and email platforms with physical FIDO2 security keys (such as YubiKeys) to neutralize session token theft.
Defense Strategies for Enterprise SOC Teams
- Endpoint Surveillance for Audio Device Access: Configure Endpoint Detection and Response (EDR) heuristics to alert on background processes accessing the Windows Core Audio API or webcam drivers.
- Application Control Restrictions: Restrict unauthorized script execution and unsigned binaries originating from `%LOCALAPPDATA%` and temporary browser cache locations.
Empfohlene Maßnahmen für IT-Sicherheitsverantwortliche
- Zeitnahe Installation der bereitgestellten Sicherheitsupdates.
- Laufende Überwachung der Netzwerktelemetrie und Protokolldateien.