Skip to content
NCSC and Allies Warn of Iranian Spyware Campaign

NCSC and Allies Warn of Iranian Spyware Campaign

Infosecurity-Magazine September 16, 2026

The UK and its allies have warned opponents of the Iranian regime that they may be subject to targeting by a Tehran-backed spyware campaign.

An advisory published yesterday by the National Cyber Security Centre (NCSC), the FBI and the Netherlands' General Intelligence and Security Service (AIVD) is designed to help dissidents, activists and journalists critical of the regime.

It warned that, in some cases, information stolen by the spyware has appeared on pro-Iranian leak sites, increasing the risk to victims’ personal safety.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said NCSC director of operations, Paul Chichester.

“With our international partners, we strongly encourage individuals at risk to familiarize themselves with the social-engineering techniques described in the advisory, and to act on the mitigation advice.”

The campaign itself revolves around the delivery of Chosen Brick: spyware designed to harvest targets’ contacts, emails and social media messages, to enable tracking of their movements, repression or worse.

The malware itself uses Windows registry keys for persistence and adds exclusions to Microsoft Defender antivirus in order to evade detection, the report revealed.

It connects to Telegram for command & control (C2) and has a wide variety of functionality including enumeration of running processes and system info, screen capture, harvesting Telegram and WhatsApp data from browsers, stealing emails and enabling the device mic for audio capture.

It can also delete files, download additional malware, and wipe the entire system, the NCSC said.

Chosen Brick is delivered via social engineering. The threat actor builds rapport with their victim on social media – usually by impersonating a or social messaging technical support. Then they persuade the victim to download a legitimate app (eg Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player) or file (e.g. MRI scan).

The advisory urged organizations concerned infection to internal or external IT providers to investigate.

“As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too,” it added.

On the plus side, the spyware interacts with numerous legitimate web services, so it’s likely to appear in corporate logs through DNS and web proxy services, the NCSC noted.

Best practice mitigations include:

Following NCSC advice on staying safe online , such as not clicking on download links or attachments

Switching on automatic updates for device OS and software

Enabling trusted AV and ensuring it’s up to date

Not disabling or ignoring smart screen warnings on file downloads

Network admins should also consider enabling phishing-resistant MFA, managing and protecting device fleets with AV, app allowlisting and other controls, and installing endpoint and network monitoring, the report advised.

The campaign has been running since at least 2025, the NCSC said.

UK and US Warn of Growing Iranian Spear Phishing Threat News 30 September 2024

UK and US Warn of Growing Iranian Spear Phishing Threat

NCSC: Iranian and Russian Groups Targeting Government, Activists and Journalists With Spearphishing News 26 January 2023

NCSC: Iranian and Russian Groups Targeting Government, Activists and Journalists With Spearphishing

NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts News 2 April 2026

NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts

NCSC Warns of Spyware Targeting Chinese and Taiwanese Diaspora News 9 April 2025

NCSC Warns of Spyware Targeting Chinese and Taiwanese Diaspora

Meta Takes Down Over 200 Covert Influence Operations Since 2017 News 19 December 2022

Meta Takes Down Over 200 Covert Influence Operations Since 2017

What’s Hot on Infosecurity Magazine?

Microsoft Releases Emergency Patch to Fix RDS Vulnerability

Revolut Confirms Data Breach Through Fake Government Requests

Hackers Exploit Maximum Severity Flaw in GitLab

OpenAI Agent Swarm Hacks RubyGems Package Manager

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

Anthropic Reveals Yet Another Cybersecurity Incident

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

NHIs Now the Number One Corporate Entry Point for Hackers

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How To Enhance Security Operations with AI-Powered Defenses

How to Manage Enterprise Cyber Resilience in the Age of AI

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust