How Does Iranian Spyware Enable Physical State Repression?

How Does Iranian Spyware Enable Physical State Repression?

Malik Haidar is a seasoned veteran in the cybersecurity trenches, known for his deep dives into the psychological and technical machinery of state-sponsored hacking. With a career built on defending multinational corporations and advising intelligence agencies, he specializes in the intersection of digital forensics and geopolitical strategy. Today, he breaks down the sophisticated Iranian campaign utilizing the “CHOSEN BRICK” malware, a tool designed to silence dissidents through highly personal psychological manipulation and technical persistence. We explore the evolution of social engineering, the architecture of state-sponsored spyware, and the terrifying transition from digital surveillance to physical real-world danger.

Threat actors are now using highly specific medical lures, such as fake MRI scans showing disk herniations, to infiltrate personal devices. What does this level of personalization reveal about the changing psychology of social engineering?

This shift toward “hyper-personalized” lures represents a chilling evolution in how intelligence services manipulate human trust. By using a fake MRI scan of a spinal injury, the attackers are not just sending a destructive file; they are exploiting a moment of extreme physical vulnerability. They often spend weeks or even months building rapport on platforms like WhatsApp or Telegram, sometimes even posing as a known contact or a helpful technical support agent to lower the victim’s guard. This is not a traditional “spray-and-pray” email campaign; it is a surgical strike designed to make the victim feel a false sense of security before the digital trap snaps shut.

Technically speaking, the CHOSEN BRICK malware seems remarkably resilient, surviving reboots and bypassing security software. How do its specific features, like the use of individual Telegram bots, complicate the response for security teams?

The architecture of CHOSEN BRICK is meticulously designed to stay hidden by mimicking the behaviors of legitimate users and common software. It specifically targets Windows systems, adding clever exclusions to Microsoft Defender so it can operate right under the nose of the operating system without triggering alarms. The most ingenious—and frustrating—part for investigators is the use of a separate Telegram bot for every single victim, which effectively silos the communication. This means that even if a security team uncovers one compromised device, the discovery does not lead them to other victims, preventing a domino effect that could expose the entire infrastructure of the campaign. Furthermore, the use of proxies and commercial cloud storage to exfiltrate data makes the malicious traffic blend seamlessly into the background noise of daily internet use.

The reports mention that this surveillance is often a precursor to physical violence, including kidnapping and assassination plots. How do attackers transform digital data into a “pattern of life” that endangers people in the real world?

When a device is infected with CHOSEN BRICK, the attackers gain a total window into the victim’s private existence, harvesting everything from contacts and email inboxes to social media messages. By turning on the device’s microphone and capturing screen content, the Iranian intelligence services can map out a victim’s daily routine with terrifying, minute-by-minute precision. We have seen these digital breadcrumbs used to facilitate more than 20 potentially lethal plots recently, as tracked by security services like MI5. This is no longer just about identity theft or data leaks; it is about providing the tactical intelligence necessary for a physical team to move in on a target, whether they are in London, Washington, or Amsterdam.

There is a notable trend of attackers moving victims away from corporate environments and toward personal devices. What makes personal hardware such an attractive landscape for these state-sponsored groups?

Corporate environments are typically hardened with enterprise-grade security, multi-factor authentication, and constant monitoring that can flag unusual outbound traffic in real-time. By social engineering a victim onto their personal phone or laptop, the attackers effectively bypass the sophisticated “moat” that a workplace provides. This is a deliberate tactic to target journalists and activists where they are most vulnerable and least protected. Once the malware is on a personal device, the attackers have unrestricted access to private photos and personal messages, which have frequently surfaced on pro-Iranian leak sites to harass, dox, and discredit the targets.

Given the connections between personas like “Handala Hack” and the Iranian Ministry of Intelligence, how should international bodies respond to this blend of digital espionage and physical threats?

The overlap between groups like Handala Hack and Homeland Justice shows that this is a centralized, state-funded machine with deep pockets and a clear mission of political repression. The U.S. State Department has already put a $10 million price tag on information leading to these hackers, which underscores the severity of the threat following high-profile compromises like the breach of a personal email account belonging to a former FBI official. We need to see more collaborative efforts between international agencies like the NCSC, FBI, and AIVD to seize leak sites and disrupt the command-and-control infrastructure. However, the real challenge lies in the fact that these actors are increasingly using proxies, including narco-traffickers, to bridge the gap between a digital hack and a physical hit, making traditional attribution much more complex.

What is your forecast for the evolution of state-sponsored surveillance against private citizens?

I anticipate that we will see a surge in “hybrid” operations where the line between cybercrime and state intelligence becomes almost invisible to the naked eye. As we move through 2026 and into 2027, the use of generative tools to create even more convincing medical and legal lures will likely make these social engineering campaigns nearly impossible to detect for the average person. We will also see a higher frequency of “hack-and-leak” operations used as psychological warfare to silence dissent before it can even form into a movement. The battleground has shifted from the high-security server room to the average living room, and our defensive strategies must evolve to protect the individual as fiercely as we currently protect the corporation.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address