www.ncsc.gov.uk 15 Sept 2026, 12:00 UTC

UK Dissidents Targeted in Iranian Spyware Campaign Using Fake MRI Results

UK Dissidents Targeted in Iranian Spyware Campaign Using Fake MRI Results
CyberSIXT Evidence Panel Source marked as original reporting

THE UK’s National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation and the Netherlands’ General Intelligence and Security Service (AIVD) have warned of an Iranian state-linked spear-phishing and spyware campaign targeting dissidents, activists and journalists, including people in the UK. The attackers have reportedly impersonated contacts on WhatsApp and Telegram, built relationships with victims and tailored social-engineering lures to their interests.

One reported lure used fake MRI test results. Sensitive information stolen during the campaign has appeared on pro-Iranian leak sites, potentially increasing victims’ personal-safety risks.

The spyware, named CHOSEN BRICK, targets Windows devices and is persistent, surviving a reboot. According to the NCSC, it can collect contacts, emails and social-media messages, capture screen content and access the device’s microphone. The NCSC assesses that Iran almost certainly uses cyber activity to support repression of people viewed as threats to its regime, but the advisory describes the activity as observed targeting rather than confirming that every attempted infection succeeded.

The agencies recommend that people at risk consult the joint advisory, follow its mitigation steps and use the NCSC’s dedicated support and free cyber-defence services. The FBI has also published technical analysis of CHOSEN BRICK.

View full article

Article by CyberSIXT