Iranian spyware campaign uses low-tech tricks to ensnare high-value targets

"We love to romanticize nation-state operations as digital wizardry, but it’s often just convincing fake profiles and low-budget spyware payloads."

Share
A view of Milad Tower rising above Tehran, the Iranian capital (Image: Unsplash)
A view of Milad Tower rising above Tehran, the Iranian capital (Image: Unsplash)

Western intelligence agencies have warned that Iran is targeting dissidents, journalists and anti-regime activists using malware called Chosen Brick.

However, the success of the spyware campaign does not appear to be down to incredible security innovation taking place in Tehran, but the regime's skilled use of the oldest trick in the book: social engineering.

In a joint statement, the FBI, the Netherlands' General Intelligence and Security Service and Britain's National Cyber Security Centre, a part of GCHQ, warned that the Iranian regime is trying to trick targets into downloading software that enables tracking of their movements.

The government-linked threat actors first research their targets in depth, then approach them over WhatsApp or Telegram, posing as trusted contacts or technical support.

After building rapport, they persuade victims to open convincing fake software, including versions of Pictory, RunwayML, Telegram, and Norton.

In one case, Tehran's agents even sent bogus MRI results, which you can see below.

A screenshot of the fake MRI scan used to snare targets (Image: NCSC)
A screenshot of the fake MRI scan used to snare targets (Image: NCSC)

READ MORE: Iran's exiled crown prince calls on hackers to attack regime's "information infrastructure"

When corporate security gets in the way, attackers try to move the victim onto a personal device.

The lure displays a legitimate-looking interface while secretly installing the Windows-only Chosen Brick malware, tracked by the FBI as Heavygram, and lets attackers capture on-screen content and listen in via a device's microphone.

Paul Chichester, National Cyber Security Centre Director of Operations, said: "Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices."

Social engineering and "long-con" impersonation

CHOSEN BRICK is no Stuxnet-style weapon of cyberwar, with the initial compromise relying on old-fashioned scamming rather than trailblazing technical excellence.

Josiah Smith, Director of Operations at OPSWAT, told Machine: "Chosen Brick fits a pattern we've tracked from Iranian state-linked operators for years. What stands out here is the lure quality (fabricated MRI results is a level of tailoring that takes real reconnaissance on the victim) and that this is a Windows-only surveillance tool with live screen and microphone capturer.

"That combination, long-con impersonation plus full desktop surveillance, is consistent with the toolset Iran's intelligence services use specifically against dissidents, journalists and activists abroad, where the goal is identifying who someone is talking to and what they're saying, not just breaching an account."

The relatively simple nature of the initial deception goes against the James Bond-style perception of cyber actors wielding impossibly advanced tools no private-sector hacker could ever hope to get their hands on.

Christiaan Beek, VP of Rapid7 Labs at Rapid7, said: “The industry loves to romanticize nation-state cyber operations as hyper-sophisticated digital wizardry, but half the time it’s just a patient operator with a convincing fake profile and a low-budget spyware payload.

"We spend a lot of money hardening enterprise perimeters, yet threat actors continuously prove they don't need to break down the front door. They just target the unmanaged personal workflow of the human who holds the keys.

"The interesting takeaway here isn't that the threat actor developed revolutionary malware. It's that the attack surface has completely detached from corporate infrastructure and attached itself to personal identity and human trust.

"The real issue isn't state actors manually running these campaigns against dozens of high-value targets today; it is what happens tomorrow when autonomous agents begin running hyper-personalized social engineering campaigns against thousands of individuals simultaneously at machine speed.”

READ MORE: “LLMs will be subverted”: Malware is evolving to attack AI defenders, SentinelOne warns

The difficulty in catching skilled social engineering actors is that traditional security tools don't tend to pick up scammers while they are building human relationships with their targets.

Patricia Titus, Field CISO at Abnormal AI, explained: "These attackers didn't exploit a vulnerability, they exploited trust. Legacy security tools are built to catch known threats and malicious payloads. They have no way to flag a convincing stranger who's been building a relationship for six weeks.

"And as AI makes it cheaper and faster to build believable fake identities at scale, this playbook won't stay confined to nation-state actors for long. Ask yourself how your team would catch that today."

In August, Iran was blamed for a cyberattack that shut down a UK power plant for four days.

Although the incident was small in scale and did not come anywhere near disrupting the national grid, it was a reminder of both the frightening vulnerability of critical infrastructure and the fact that wars fought a long way awake can now have frightening new local impacts.

Follow Machine on LinkedIn