Back Eutoday Britain, US and Netherlands warn of Iranian spyware targeting journalists
Dutch intelligence says victims in the Netherlands have been informed after a joint investigation identified malicious software used to monitor Iranian critics living in the West.
Britain, the United States and the Netherlands issued a joint warning on 15 September Iranian state-linked hackers targeting journalists, activists and dissidents with spyware capable of stealing private communications and monitoring their devices.
The joint cybersecurity advisory , published by Britain’s National Cyber Security Centre, the FBI and the Dutch General Intelligence and Security Service, identifies a malware family called CHOSEN BRICK. The agencies warn that personal details belonging to some victims have appeared on pro-Iranian leak websites, potentially increasing risks to their safety.
The Netherlands’ intelligence service, the AIVD, confirmed that victims in the Netherlands had been informed . It said the operation sought sensitive information critics of the Iranian authorities living in the West. Its announcement did not identify those affected or disclose their number.
The Dutch findings establish a direct European dimension to the campaign: people living outside Iran are being targeted through their personal equipment and accounts. For journalists, the potential consequences extend beyond the disclosure of their own correspondence to the identification of confidential sources and professional contacts.
According to the British announcement , Iranian state cyber actors have tried to persuade targets to download software enabling surveillance, including the tracking of their movements. The warning addresses both individuals at risk and organisations responsible for protecting their systems.
Building trust before delivering malware
The AIVD describes an approach that begins with through social media. Attackers develop a relationship with the target before encouraging them to download and open a file presented as legitimate software.
The malicious files can impersonate familiar applications, including Telegram, KeePass, Flash Player, Pictory and RunwayML. The use of these names is part of the deception described by investigators; it does not establish that the genuine products or their developers were involved.
CHOSEN BRICK specifically targets Windows devices and remains active after a restart, according to the Dutch service. Once installed, it can change or disable security settings and provide access to contacts, email and social media information.
The reported surveillance capabilities also include capturing screen content and accessing a device’s microphone. Iran’s embassy in London did not immediately respond to Reuters’ request for .
For a newsroom, the distinction between an account breach and surveillance of an entire device matters. Access to a journalist’s computer could expose material across several services, including research, correspondence and information forthcoming meetings. These are potential consequences of the capabilities described, rather than a published account of what happened to every victim.
Earlier warnings targeted approaches
British and American authorities have previously warned Iranian operations using personal relationships and professional interests to obtain access to accounts.
In a separate advisory issued in 2024 , the NCSC described attackers working on behalf of Iran’s Islamic Revolutionary Guard Corps impersonating contacts and building rapport before directing targets to false login pages.
That warning covered people connected to Iranian and Middle Eastern affairs, including journalists, activists, government officials and think-tank personnel. Approaches included invitations to conferences, discussions of foreign policy and impersonation of family members or prominent journalists.
The earlier operation illustrates the established use of tailored approaches against such groups. It should not be treated as proof that the same operators conducted the newly disclosed spyware campaign.
Tuesday’s publication adds technical information malicious software and advice for investigating possible compromise. The inclusion of information victims’ details appearing on leak sites also connects the theft of private material with its subsequent public exposure.
That creates two distinct problems for those affected: removing unauthorised access and assessing the consequences of information already taken. Restoring control of a device cannot, by itself, retrieve copies of correspondence or personal details held elsewhere.
The AIVD advises users to obtain software directly from legitimate websites or official app stores, keep systems updated and leave antivirus protection enabled. It also warns against ignoring Windows SmartScreen alerts. People who suspect they have been targeted can the Dutch intelligence service or police, while organisations can use the joint advisory to investigate possible infections.
EUToday publishes articles from a variety of outside sources which express a wide range of viewpoints.Opinions expressed in these articles are not necessarily those of EUToday.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
