Iranian Hackers Deploy Fake Medical Data to Target Regime Critics, UK Agency Says
Iranian cyber operatives used counterfeit MRI scan results to breach a computer belonging to a person the regime deems an adversary, according to the United Kingdom’s National Cyber Security Centre.
The NCSC disclosed that the malicious files were sent as attachments in emails purporting to contain medical imaging results, a ploy designed to exploit the recipient’s interest in health information and to bypass technical defenses.
When the attachment was opened, malware installed a remote‑access tool that allowed operators to exfiltrate data and monitor the victim’s communications. The centre linked the incident to a broader Iranian effort to intimidate and silence critics abroad.
Iran has a documented history of employing cyber capabilities to track, harass or silence dissidents, activists and journalists. The agency noted that similar tactics have been observed in other campaigns targeting individuals seen as threats to the regime.
Security experts say the use of seemingly innocuous medical documents is part of a growing trend where threat actors disguise malicious payloads as everyday files, making detection harder for users and automated security solutions.
The NCSC urged organizations and individuals to verify the authenticity of unsolicited medical documents, employ multi‑factor authentication and keep software up to date. It also signaled that the UK will continue to monitor and publicise state‑linked cyber operations that aim to undermine human rights.
Comments (0)
Be the first to comment.
Join the discussion