Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”
British, American and Dutch security agencies issued a warning on Tuesday exposing a spyware tool being used by Iranian state-sponsored hackers to target individuals perceived as posing a threat to the regime.
The malware, named CHOSEN BRICK by British intelligence, has been delivered using a range of lures — including a fake MRI scan of a disk herniation — sent to victims after extensive social engineering campaigns to earn their trust.
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”
Source: https://therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
Related breach coverage
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists2026-09-15
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
- Chosen Brick, Iran’s Surveillance Malware2026-09-17
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]
- Iranian cyber targeting of dissidents, activists and journalists2026-09-15
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
- Trump Targets Foreign Technology in New U.S. Power Grid Security Order2026-08-28
Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of […]