British authorities have issued a rare cyber alert warning that Iran is using sophisticated spyware disguised as fabricated MRI scan results to target dissidents worldwide. The advisory was released jointly by Britain’s National Cyber Security Centre (NCSC), the United States Federal Bureau of Investigation (FBI), and the Netherlands’ security service, underscoring growing concerns over Tehran’s digital surveillance activities.
According to the alert, Iranian operatives have employed messaging platforms such as WhatsApp and Telegram to impersonate individuals known to their targets, primarily Iranian dissidents living abroad and journalists critical of the regime. This approach is used to build trust before persuading victims to download malicious files appearing to be legitimate medical documents, specifically MRI test results. The spyware identified as “Chosen Brick” is designed to collect sensitive information, including contacts, emails, and social media communications. It can also potentially activate the device’s microphone to conduct covert eavesdropping.
The malware, which specifically affects Windows devices, is described as “persistent,” capable of remaining active even after the device has been restarted. The NCSC noted that some stolen data has surfaced on pro-Iranian leak websites, potentially exposing victims to further harassment or targeting.
Paul Chichester, director of operations at the NCSC, emphasized the regime’s ruthlessness in using digital tools to suppress dissent. “This campaign reveals how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” he said. Chichester urged those at risk to familiarize themselves with the social engineering tactics detailed in the advisory and to adopt recommended security measures.
While Iran’s use of spyware against dissidents is not new—the FBI had previously issued alerts following heightened tensions between the US and Iran earlier this year—this marks Britain’s first significant cybersecurity warning since the outbreak of the conflict in the Middle East. In March, the NCSC assessed that there was no substantial change in the direct cyber threat posed by Iran to the UK at that time but acknowledged that the situation remains fluid.
The warning comes shortly after the arrest of two individuals in London—aged 42 and 60—on suspicion of assisting Iran’s intelligence services. Both were detained under the National Security Act 2023 and later released on bail until late October. Commander Helen Flanagan, head of Counter Terrorism Policing London, stated there was no imminent threat to the broader public despite the arrests.
The coordinated advisory from the UK, US, and Dutch security agencies aims to alert potential targets and reinforce protective measures amid an intensifying cyber threat landscape linked to the Iranian government’s efforts to monitor and intimidate opposition figures overseas.
